CVE-2020-25097: Debian Linux

High severity, CVSS 8.6. EPSS: 7.3% chance of exploitation in the next 30 days.

An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
  • Netapp Cloud Manager: affected versions not specified
  • Squid-Cache Squid: from 2.0, before 4.14 (fixed in 4.14); from 5.0.1, before 5.0.5 (fixed in 5.0.5)

Published 2021-03-19. Last modified 2026-06-17.