CVE-2013-1839: Squid-Cache Squid

High severity, CVSS 7.8. EPSS: 18.3% chance of exploitation in the next 30 days.

The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a "," character in an Accept-Language header.

Affected products

  • Squid-Cache Squid: version 3.2.0.1 only; version 3.2.0.2 only; version 3.2.0.3 only; version 3.2.0.4 only; version 3.2.0.5 only; version 3.2.0.6 only; …

Published 2013-09-30. Last modified 2026-06-16.