PT-2023-7760 · Squid+10 · Squid+11

Joshua Rogers

·

Published

2023-10-12

·

Updated

2026-03-29

·

CVE-2023-50269

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squid versions 2.6 through 2.7.STABLE9 Squid versions 3.1 through 5.9 Squid versions 6.0.1 through 6.5
Description The issue is related to an Uncontrolled Recursion bug in the Squid caching proxy, which may allow a remote client to perform a Denial of Service attack against HTTP Request parsing. This can be achieved by sending a large X-Forwarded-For header when the follow x forwarded for feature is configured. The problem is associated with the follow x forwarded for() function and the handling of X-Forwarded-For HTTP request headers.
Recommendations For Squid versions 2.6 through 2.7.STABLE9, update to a version that includes the fix, such as Squid version 6.6, or apply patches from Squid's patch archives. For Squid versions 3.1 through 5.9, update to a version that includes the fix, such as Squid version 6.6, or apply patches from Squid's patch archives. For Squid versions 6.0.1 through 6.5, update to Squid version 6.6 or apply patches from Squid's patch archives. As a temporary workaround, consider disabling the follow x forwarded for feature to minimize the risk of exploitation.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:1375
ALSA-2024:1376
ALT-PU-2024-1077
ALT-PU-2024-2157
ALT-PU-2024-9370
AZL-32251
BDU:2023-08827
CESA-2024_1375
CVE-2023-50269
DLA-3709-1
DSA-5637-1
GHSA-WGQ4-4CFG-C4X3
MGASA-2024-0102
OESA-2023-1947
OPENSUSE-SU-2024:13631-1
RHSA-2024:0397
RHSA-2024:0771
RHSA-2024:0772
RHSA-2024:0773
RHSA-2024:1085
RHSA-2024:1153
RHSA-2024:1375
RHSA-2024:1376
RHSA-2024:1787
RHSA-2024_1375
RHSA-2024_1376
RHSA-2024_1787
ROSA-SA-2024-2479
ROSA-SA-2025-2595
SUSE-SU-2024:0296-1
SUSE-SU-2024:0298-1
SUSE-SU-2024:0455-1
SUSE-SU-2024_0296-1
SUSE-SU-2024_0298-1
SUSE-SU-2024_0455-1
USN-6594-1
USN-6857-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu