CVE-2024-37894: Squid-Cache Squid
Medium severity, CVSS 6.3. EPSS: 6.3% chance of exploitation in the next 30 days.
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack.
Affected products
- Squid-Cache Squid: from 3.0, before 6.10 (fixed in 6.10)
Published 2024-06-25. Last modified 2026-06-17.