CVE-2025-62168CWE-209CWE-550

Squid vulnerable to information disclosure via authentication credential leakage in error handling

Critical · published October 17, 2025

Patch now

High probability of exploitation

CVSS calls it critical at 10.0. It sits in the 99.1th percentile for exploit probability.

CVSS v3.1
10.0
EPSS
63%
Percentile
99.1
In the wild
Unconfirmed
What it is

🚨 A sneaky oversight in Squid means HTTP authentication credentials can slip through error messages! 🔥 Think of it like a hotel receptionist who accidentally leaves the guest list out for everyone to see — that list contains all the guests' room keys, just waiting to be grabbed! An attacker could exploit this vulnerability to harvest sensitive authentication tokens from trusted clients. This could lead to unauthorized access or data leaks from web applications that rely on Squid for load balancing — a recipe for absolute chaos!

Put simply

Think of it like a hotel receptionist who accidentally leaves the guest list out for everyone to see — that list contains all the guests' room keys, just waiting to be grabbed! This vulnerability in Squid allows error handling to expose HTTP authentication credentials, enabling attackers to bypass traditional browser security measures and potentially gain access to internal web application credentials.

What to do

An attacker could exploit this vulnerability to harvest sensitive authentication tokens from trusted clients. This could lead to unauthorized access or data leaks from web applications that rely on Squid for load balancing — a recipe for absolute chaos! Upgrade Squid to version 7.2 immediately to close this critical hole. As a temporary fix, disable debug information in your squid.conf by setting email_err_data off, until you can patch. Don't wait! You've got this! Follow these steps, and you'll be one step closer to securing your setup. 🛡️

The record
Technical detail
CVSS v3.1
10.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.62871 · 99.1th percentile
Weaknesses
CWE-209 · Generation of Error Message Containing Sensitive Information; CWE-550 · Server-generated Error Message Containing Sensitive Information
Published
2025-10-17T16:21Z
EPSS history
Timeline
  • 17 OCT 16:21Z
    Squid vulnerable to information disclosure via authentication credential leakage in error handling
    cvelistv5