PT-2025-42624 · Squid+10 · Squid+11

Published

2025-09-14

·

Updated

2026-04-12

·

CVE-2025-62168

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Squid versions prior to 7.2 Squid versions 3.x through 3.5.28 Squid versions 4.x through 4.17 Squid versions 5.x through 5.9 Squid versions 6.x through 6.14 Squid versions 7.x through 7.1
Description Squid, a caching proxy for the Web, contains a flaw where it fails to redact HTTP authentication credentials in error handling. This allows an attacker to potentially bypass browser security protections and obtain sensitive information, such as credentials or security tokens, used by trusted clients. The issue does not require HTTP authentication to be configured. The vulnerability is related to the email err data parameter. Approximately 40 million to 47.2 million instances are estimated to be vulnerable worldwide. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing.
Recommendations For versions prior to 7.2, update to version 7.2 or later. As a workaround for versions prior to 7.2, disable debug information in administrator mailto links by configuring email err data off in the squid.conf file.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

ALSA-2025:19107
ALSA-2025:20935
ALSA-2025:21002
ALSA-2025_19107
ALSA-2025_20935
ALT-PU-2025-14197
AZL-68562
AZL-68589
BDU:2025-13226
CESA-2025_19107
CVE-2025-62168
DLA-4369-1
DSA-6047-1
GHSA-C8CC-PHH7-XMXR
INFSA-2025_19107
INFSA-2025_20935
MGASA-2026-0094
OESA-2025-2531
OESA-2025-2606
OESA-2025-2607
OESA-2026-1551
OPENSUSE-SU-2025:15715-1
OPENSUSE-SU-2026:20027-1
RHSA-2025:19107
RHSA-2025:19114
RHSA-2025:19115
RHSA-2025:19118
RHSA-2025:19167
RHSA-2025:19277
RHSA-2025:19398
RHSA-2025:19967
RHSA-2025:20935
RHSA-2025:21002
RHSA-2025:21065
RHSA-2025:21066
RHSA-2025:21090
RHSA-2025_19107
RHSA-2025_20935
SUSE-SU-2025:3902-1
SUSE-SU-2025:4026-1
SUSE-SU-2025:4029-1
SUSE-SU-2025:4099-1
SUSE-SU-2025_3902-1
SUSE-SU-2025_4026-1
SUSE-SU-2025_4029-1
SUSE-SU-2025_4099-1
SUSE-SU-2026:20078-1
USN-7845-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu