CVE-2020-15811: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 4.1% chance of exploitation in the next 30 days.
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content from an arbitrary source. Squid uses a string search instead of parsing the Transfer-Encoding header to find chunked encoding. This allows an attacker to hide a second request inside Transfer-Encoding: it is interpreted by Squid as chunked and split out into a second request delivered upstream. Squid will then deliver two distinct responses to the client, corrupting any downstream caches.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
- Opensuse Leap: version 15.1 only; version 15.2 only
- Squid-Cache Squid: before 4.13 (fixed in 4.13); from 5.0, before 5.0.4 (fixed in 5.0.4)
Published 2020-09-02. Last modified 2026-06-17.