CVE-2016-10003: Squid-Cache Squid
High severity, CVSS 7.5. EPSS: 4.8% chance of exploitation in the next 30 days.
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
Affected products
- Squid-Cache Squid: from 3.5.0.1, before 3.5.23 (fixed in 3.5.23); from 4.0.1, before 4.0.17 (fixed in 4.0.17)
Published 2017-01-27. Last modified 2026-06-17.