CVE-2016-10002: Debian Linux
High severity, CVSS 7.5. EPSS: 6.8% chance of exploitation in the next 30 days.
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
Affected products
- Debian Debian Linux: version 8.0 only
- Squid-Cache Squid: version 3.1.10 only; version 3.1.11 only; version 3.1.12 only; version 3.1.14 only; version 3.1.15 only; version 3.1.16 only; …
Published 2017-01-27. Last modified 2026-06-17.