CVE-2023-46846: Red Hat Enterprise Linux

Medium severity, CVSS 5.3. EPSS: 6.2% chance of exploitation in the next 30 days.

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

Affected products

  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux Eus: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
  • Red Hat Enterprise Linux For Arm 64: version 8.0_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only; version 9.2 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only; version 9.2 only
  • Squid-Cache Squid: from 2.6, before 6.4 (fixed in 6.4)

Published 2023-11-03. Last modified 2026-06-17.