CVE-2023-46848: Red Hat Enterprise Linux

High severity, CVSS 7.5. EPSS: 10.2% chance of exploitation in the next 30 days.

Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.

Affected products

  • Red Hat Enterprise Linux: version 9.0 only
  • Red Hat Enterprise Linux Eus: version 9.2 only
  • Red Hat Enterprise Linux Server Aus: version 9.2 only
  • Red Hat Enterprise Linux Server Tus: version 9.2 only
  • Squid-Cache Squid: from 5.0.3, before 6.4 (fixed in 6.4)

Published 2023-11-03. Last modified 2026-06-17.