CVE-2025-54574

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*

History

05 Nov 2025, 17:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/11/05/5 -
  • () https://lists.debian.org/debian-lts-announce/2025/09/msg00027.html -
References () https://github.com/squid-cache/squid/security/advisories/GHSA-w4gv-vw3f-29g3 - Patch, Vendor Advisory, Mitigation () https://github.com/squid-cache/squid/security/advisories/GHSA-w4gv-vw3f-29g3 - Mitigation, Patch, Vendor Advisory

Information

Published : 2025-08-01 18:15

Updated : 2025-11-05 17:15


NVD link : CVE-2025-54574

Mitre link : CVE-2025-54574

CVE.ORG link : CVE-2025-54574


JSON object : View

Products Affected

squid-cache

  • squid
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write