CVE-2019-18676: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 9.2% chance of exploitation in the next 30 days.

An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security checks; any remote client that can reach the proxy port can trivially perform the attack via a crafted URI scheme.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only
  • Squid-Cache Squid: from 3.0, up to and including 3.5.28; from 4.0, up to and including 4.8

Published 2019-11-26. Last modified 2026-06-17.