CVE-2016-2572: Squid-Cache Squid

High severity, CVSS 7.5. EPSS: 10.2% chance of exploitation in the next 30 days.

http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

Affected products

  • Squid-Cache Squid: version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; version 4.0.6 only

Published 2016-02-27. Last modified 2026-06-17.