CVE-2023-46846: Red Hat Enterprise Linux
Medium severity, CVSS 5.3. EPSS: 6.2% chance of exploitation in the next 30 days.
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
Affected products
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Red Hat Enterprise Linux Eus: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
- Red Hat Enterprise Linux For Arm 64: version 8.0_aarch64 only
- Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only
- Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only
- Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only; version 9.2 only
- Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only; version 9.2 only
- Squid-Cache Squid: from 2.6, before 6.4 (fixed in 6.4)
Published 2023-11-03. Last modified 2026-06-17.