CVE-2019-18677: Canonical Ubuntu Linux

Medium severity, CVSS 6.1. EPSS: 7.2% chance of exploitation in the next 30 days.

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Fedoraproject Fedora: version 30 only; version 31 only
  • Squid-Cache Squid: from 2.0, up to and including 2.7; from 3.0, up to and including 3.5.28; from 4.0, up to and including 4.8; version 2.7 only

Published 2019-11-26. Last modified 2026-06-17.