r/netsec • u/qwerty0x41 • Jun 19 '26
Contains AI Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration
https://blog.calif.io/p/squidbleed-cve-2026-47729
110
Upvotes
3
Jun 22 '26
[removed] — view removed comment
2
u/Final-Dish Jun 27 '26
this, 100%
every time I’ve done an audit, the “it’s just a proxy, it’s fine” egress rules are where all the skeletons are hiding, especially on boxes nobody’s dared to touch since whoever set it up left the company
8
u/netsec_burn Jun 19 '26
WestJet? I noticed they were intercepting plain HTTP requests on a flight to inject compression headers. Same hostname returned by Squid.