CVE-2026-61642
Public on 2026-09-18
Modified on 2026-09-18
Description
Due to a CWE-841 Improper Enforcement of Behavioral Workflow
bug Squid is vulnerable to a Request Smuggling attack against
HTTP/1.1 Transfer-Encoding.
This problem allows a trusted client to perform an HTTP Request
Smuggling attack when HTTP/1.1 is used. Bypassing security
mechanisms that may be in place between attacker and Squid.
When there is an HTTP cache operating prior to the affected
Squid, this Request Smuggling attack also allows the attacker
to poison that web cache and store arbitrary malicious content
at any URL for delivery to other clients future requests.
bug Squid is vulnerable to a Request Smuggling attack against
HTTP/1.1 Transfer-Encoding.
This problem allows a trusted client to perform an HTTP Request
Smuggling attack when HTTP/1.1 is used. Bypassing security
mechanisms that may be in place between attacker and Squid.
When there is an HTTP cache operating prior to the affected
Squid, this Request Smuggling attack also allows the attacker
to poison that web cache and store arbitrary malicious content
at any URL for delivery to other clients future requests.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | squid | Pending Fix | ||
| Amazon Linux 2 - Squid4 Extra | squid | No Fix Planned | ||
| Amazon Linux 2023 | squid | Pending Fix | ||
| Amazon Linux 2027 Preview | squid | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |