VORANT. Threat Intelligence Sign in Get the full feed

Squid proxy patches confidentiality flaws

medium vulnerability

Multiple vulnerabilities in Squid proxy versions before 7.6 allow attackers to compromise data confidentiality.

The French national cybersecurity agency ANSSI has published an advisory regarding multiple security vulnerabilities affecting Squid proxy server versions prior to 7.6. The flaws enable attackers to breach data confidentiality, with one vulnerability's specifics not yet disclosed by the vendor.

Two CVEs have been assigned to track these issues: CVE-2026-47729 and CVE-2026-50012. GitHub security advisories GHSA-5vmx-9x64-9284 and GHSA-8c37-pxjq-qwrg were published on June 23, 2026, providing vendor-specific details. Organizations running affected Squid versions should consult the vendor bulletins and apply patches to version 7.6 or later.

Squid is a widely-deployed caching and forwarding HTTP proxy used across enterprise networks, making timely patching important for organizations relying on it for web traffic filtering and optimization.

Mentioned in this report

Vulnerabilities CVE-2026-47729CVE-2026-50012

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0795

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free