Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Squid HTTP Proxy project

Squid HTTP Proxy project Vendor Cyber Rating & Cyber Score

squid-cache.org

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. It reduces bandwidth and improves response times by caching and reusing frequently-requested web pages. Squid has extensive access controls and makes a great server accelerator. It runs on most available operating systems, including Windows and is licensed under the GNU GPL.


SHPP A.I CyberSecurity Scoring

SHPP
Company Information
Website:http://www.squid-cache.org
Employees number:1
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:squid-cache.org
SHPP Risk Score (AI oriented)
Between 750 and 799
logo
SHPPIT Services and IT Consulting
Updated:
22/06/2026
780/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SHPP Global Score (TPRM)
xxxx
logo
SHPPIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SHPP
SHPPFair
Current Score
780Baa (FAIR)
01000
2 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
781Before Incident
AUGUST 2026
781Before Incident
JULY 2026
781Before Incident
JUNE 2026
780Before Incident
MAY 2026
780Before Incident
APRIL 2026
781Before Incident
Vulnerability
01 Apr 2026SHPP
Squid Proxy: Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

Squid Proxy Vulnerability 'Squidbleed' Exposes Sensitive Data Since 1997

780After Incident
CRITICAL-1
SQU1782148033
Squid Proxy Vulnerability "Squidbleed" Exposes Sensitive Data Since 1997 Security researchers at Calif.io have uncovered a critical memory leak vulnerability in Squid Proxy, dubbed Squidbleed (CVE-2026-47729), which has persisted in the software since 1997. The flaw mirrors the infamous Heartbleed bug, allowing attackers to read beyond memory buffer boundaries in Squid’s FTP parser, potentially exposing sensitive data from prior HTTP requests. Squid, a widely deployed open-source web proxy, is used to cache and optimize traffic for protocols like HTTP, HTTPS, and FTP, commonly found in corporate networks, schools, and public Wi-Fi hotspots. The vulnerability poses the greatest risk in shared proxy environments, where an attacker controlling an FTP server could silently harvest authentication credentials, session tokens, and API keys from other users. The exposure is limited to cleartext HTTP traffic and deployments where Squid terminates TLS. While HTTPS traffic relayed via CONNECT tunnels remains unaffected, many enterprises and legacy systems still transmit sensitive data over unencrypted HTTP, expanding the potential attack surface. The flaw was identified with assistance from Anthropic’s Claude Mythos AI model. A patch was integrated into Squid version 8 in April 2026 and backported to version 7.6 in June 2026. Organizations can mitigate the risk by disabling FTP support if unused. This discovery follows Calif.io’s recent AI-assisted findings, including a high-severity OpenSSL vulnerability and the HTTP/2 Bomb denial-of-service technique. The firm continues to leverage AI in vulnerability research, highlighting its growing role in cybersecurity threat detection.
INCIDENT DETAILS -
TYPE
Memory Leak Vulnerability
IMPACT
Data Compromised: authentication credentials, session tokens, API keysSystems Affected: Squid Proxy versions prior to 7.6 and 8Identity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Authentication credentials, session tokens, API keysSensitivity Of Data: HighData Exfiltration: PotentialData Encryption: Limited to cleartext HTTP trafficPersonally Identifiable Information: Potential
MARCH 2026
781Before Incident
FEBRUARY 2026
781Before Incident
JANUARY 2026
781Before Incident
DECEMBER 2025
781Before Incident
NOVEMBER 2025
781Before Incident
OCTOBER 2025
781Before Incident
JANUARY 1997
781Before Incident
Vulnerability
18 Jan 1997SHPP
Squid Proxy: 29-Year-Old ‘Squidbleed’ Vulnerability Discovered With the Aid of Claude Mythos Preview

Squidbleed: 29-Year-Old Vulnerability in Squid Proxy Exposes Sensitive Data

780After Incident
CRITICAL-1
SQU1782145878
Squidbleed: 29-Year-Old Vulnerability in Squid Proxy Exposes Sensitive Data Security researchers at Calif.io have uncovered a critical memory disclosure vulnerability in Squid Proxy, dubbed Squidbleed, which has remained undetected since 1997. The flaw, discovered with the help of Anthropic’s Claude Mythos Preview AI, allows attackers to silently leak HTTP headers including passwords and API keys from other users sharing the same proxy. ### The Vulnerability Squidbleed (CVE pending) is a heap buffer overread in Squid’s FTP directory listing parser. The bug stems from a 1997 commit that introduced logic to handle NetWare FTP servers, which used extra whitespace in directory listings. A critical oversight in the `strchr` function where the null terminator (`\0`) is treated as part of the search string causes the parser to read beyond allocated memory when no filename follows a timestamp. This results in a confirmed heap overread of up to 4,065 bytes, exposing stale HTTP request data from previously freed 4KB buffers. Since Squid reuses memory without zeroing it, an attacker controlling an FTP server can trigger the flaw via a malformed directory listing, causing the proxy to return sensitive data such as Authorization headers and session tokens as part of the FTP response. ### Attack Conditions The exploit requires: - FTP support enabled (default in Squid). - An attacker-controlled FTP server reachable on TCP port 21 (allowed by Squid’s default `Safe_ports` ACL). - Victim traffic passing through the proxy as cleartext HTTP (HTTPS CONNECT tunnels are unaffected). Researchers demonstrated the attack by leaking Authorization headers from a login page via a shared Squid proxy. A proof-of-concept exploit is publicly available on GitHub. ### The Fix & Mitigation The vulnerability was patched with a single-line null check before each `strchr` call: ```c - while (strchr(w_space, *copyFrom)) + while (copyFrom && strchr(w_space, copyFrom)) ``` The fix has been merged into Squid’s repository. Administrators are advised to disable FTP support unless explicitly required, as modern browsers (including Chromium-based ones) no longer support FTP, making legitimate proxy traffic rare. ### AI-Assisted Discovery The flaw was identified using Claude Mythos Preview, which flagged the `strchr` null terminator behavior during an analysis of Squid’s FTP state machine. This follows a growing trend of AI-assisted security audits, with the team previously uncovering an HTTP/2 vulnerability using OpenAI’s Codex Cyber. The discovery highlights how LLMs trained on C standards can detect subtle API contract violations that evade traditional code reviews.
INCIDENT DETAILS -
TYPE
Memory Disclosure Vulnerability
IMPACT
Data Compromised: HTTP headers (including passwords, API keys, Authorization headers, session tokens)Systems Affected: Squid Proxy (versions with FTP support enabled)Identity Theft Risk: High (due to exposure of sensitive credentials)
DATA BREACH
Type Of Data Compromised: HTTP headers (Authorization headers, session tokens, passwords, API keys)Sensitivity Of Data: High (personally identifiable and authentication data)Data Exfiltration: Yes (via malformed FTP responses)Personally Identifiable Information: Yes (session tokens, credentials)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SHPP ?
?
What was SHPP's A.I Rankiteo Cyber Score in August 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in July 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in June 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SHPP's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SHPP's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SHPP's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on SHPP's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SHPP ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SHPP's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?