CVE-2020-26154: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.

Affected products

Published 2020-09-30. Last modified 2026-06-17.