CVE-2020-25097: Debian Linux
High severity, CVSS 8.6. EPSS: 7.3% chance of exploitation in the next 30 days.
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
- Netapp Cloud Manager: affected versions not specified
- Squid-Cache Squid: from 2.0, before 4.14 (fixed in 4.14); from 5.0.1, before 5.0.5 (fixed in 5.0.5)
Published 2021-03-19. Last modified 2026-06-17.