# Squid proxy patches confidentiality flaws

Published: 2026-06-23 · Severity: medium
Canonical: https://vorant.io/reports/8352def0-db2e-5d95-aeb7-6652119899c8/squid-proxy-patches-confidentiality-flaws

> Multiple vulnerabilities in Squid proxy versions before 7.6 allow attackers to compromise data confidentiality.

The French national cybersecurity agency ANSSI has published an advisory regarding multiple security vulnerabilities affecting Squid proxy server versions prior to 7.6. The flaws enable attackers to breach data confidentiality, with one vulnerability's specifics not yet disclosed by the vendor.

Two CVEs have been assigned to track these issues: CVE-2026-47729 and CVE-2026-50012. GitHub security advisories GHSA-5vmx-9x64-9284 and GHSA-8c37-pxjq-qwrg were published on June 23, 2026, providing vendor-specific details. Organizations running affected Squid versions should consult the vendor bulletins and apply patches to version 7.6 or later.

Squid is a widely-deployed caching and forwarding HTTP proxy used across enterprise networks, making timely patching important for organizations relying on it for web traffic filtering and optimization.

## Mentioned in this report

- Vulnerabilities: CVE-2026-47729, CVE-2026-50012

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0795

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8352def0-db2e-5d95-aeb7-6652119899c8/squid-proxy-patches-confidentiality-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
