USN-7845-1: Squid vulnerability
USN-7845-1: Squid vulnerability
Publication date: 28 October 2025
Overview: Squid would allow unintended access to sensitive information over the network.
Packages
- squid - Web proxy cache server
- squid3 - Web proxy cache server
Details
Leonardo Giovannini discovered that Squid failed to redact HTTP
Authentication credentials in a default configuration. An attacker could
possibly use this issue to obtain sensitive information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
25.10 questing
- squid – 6.13-1ubuntu4.1
25.04 plucky - squid – 6.13-1ubuntu1.2
24.04 LTS noble - squid – 6.13-0ubuntu0.24.04.3
22.04 LTS jammy - squid – 5.9-0ubuntu0.22.04.4
20.04 LTS focal - squid – 4.10-1ubuntu1.13+esm1
18.04 LTS bionic - squid – 3.5.27-1ubuntu1.14+esm4
- squid3 – 3.5.27-1ubuntu1.14+esm4
16.04 LTS xenial - squid – 3.5.12-1ubuntu7.16+esm5
- squid3 – 3.5.12-1ubuntu7.16+esm5

