SHPP A.I CyberSecurity Scoring
SHPP
Company Information
Website:http://www.squid-cache.org
Employees number:1
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:squid-cache.org
SHPP Risk Score (AI oriented)
Between 750 and 799
SHPPIT Services and IT Consulting
Updated:
22/06/2026
22/06/2026
780/1000
Fair
Baa
SHPP Global Score (TPRM)
xxxx
SHPPIT Services and IT Consulting
Score locked

SHPPFair
Current Score
780Baa (FAIR)
01000
2 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
781
AUGUST 2026
781
JULY 2026
781
JUNE 2026
780
MAY 2026
780
APRIL 2026
781
Vulnerability
01 Apr 2026 • SHPP
Squid Proxy: Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
Squid Proxy Vulnerability 'Squidbleed' Exposes Sensitive Data Since 1997
780
CRITICAL-1
SQU1782148033
Squid Proxy Vulnerability "Squidbleed" Exposes Sensitive Data Since 1997
Security researchers at Calif.io have uncovered a critical memory leak vulnerability in Squid Proxy, dubbed Squidbleed (CVE-2026-47729), which has persisted in the software since 1997. The flaw mirrors the infamous Heartbleed bug, allowing attackers to read beyond memory buffer boundaries in Squid’s FTP parser, potentially exposing sensitive data from prior HTTP requests.
Squid, a widely deployed open-source web proxy, is used to cache and optimize traffic for protocols like HTTP, HTTPS, and FTP, commonly found in corporate networks, schools, and public Wi-Fi hotspots. The vulnerability poses the greatest risk in shared proxy environments, where an attacker controlling an FTP server could silently harvest authentication credentials, session tokens, and API keys from other users.
The exposure is limited to cleartext HTTP traffic and deployments where Squid terminates TLS. While HTTPS traffic relayed via CONNECT tunnels remains unaffected, many enterprises and legacy systems still transmit sensitive data over unencrypted HTTP, expanding the potential attack surface.
The flaw was identified with assistance from Anthropic’s Claude Mythos AI model. A patch was integrated into Squid version 8 in April 2026 and backported to version 7.6 in June 2026. Organizations can mitigate the risk by disabling FTP support if unused.
This discovery follows Calif.io’s recent AI-assisted findings, including a high-severity OpenSSL vulnerability and the HTTP/2 Bomb denial-of-service technique. The firm continues to leverage AI in vulnerability research, highlighting its growing role in cybersecurity threat detection.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
781
FEBRUARY 2026
781
JANUARY 2026
781
DECEMBER 2025
781
NOVEMBER 2025
781
OCTOBER 2025
781
JANUARY 1997
781
Vulnerability
18 Jan 1997 • SHPP
Squid Proxy: 29-Year-Old ‘Squidbleed’ Vulnerability Discovered With the Aid of Claude Mythos Preview
Squidbleed: 29-Year-Old Vulnerability in Squid Proxy Exposes Sensitive Data
780
CRITICAL-1
SQU1782145878
Squidbleed: 29-Year-Old Vulnerability in Squid Proxy Exposes Sensitive Data
Security researchers at Calif.io have uncovered a critical memory disclosure vulnerability in Squid Proxy, dubbed Squidbleed, which has remained undetected since 1997. The flaw, discovered with the help of Anthropic’s Claude Mythos Preview AI, allows attackers to silently leak HTTP headers including passwords and API keys from other users sharing the same proxy.
### The Vulnerability
Squidbleed (CVE pending) is a heap buffer overread in Squid’s FTP directory listing parser. The bug stems from a 1997 commit that introduced logic to handle NetWare FTP servers, which used extra whitespace in directory listings. A critical oversight in the `strchr` function where the null terminator (`\0`) is treated as part of the search string causes the parser to read beyond allocated memory when no filename follows a timestamp.
This results in a confirmed heap overread of up to 4,065 bytes, exposing stale HTTP request data from previously freed 4KB buffers. Since Squid reuses memory without zeroing it, an attacker controlling an FTP server can trigger the flaw via a malformed directory listing, causing the proxy to return sensitive data such as Authorization headers and session tokens as part of the FTP response.
### Attack Conditions
The exploit requires:
- FTP support enabled (default in Squid).
- An attacker-controlled FTP server reachable on TCP port 21 (allowed by Squid’s default `Safe_ports` ACL).
- Victim traffic passing through the proxy as cleartext HTTP (HTTPS CONNECT tunnels are unaffected).
Researchers demonstrated the attack by leaking Authorization headers from a login page via a shared Squid proxy. A proof-of-concept exploit is publicly available on GitHub.
### The Fix & Mitigation
The vulnerability was patched with a single-line null check before each `strchr` call:
```c
- while (strchr(w_space, *copyFrom))
+ while (copyFrom && strchr(w_space, copyFrom))
```
The fix has been merged into Squid’s repository. Administrators are advised to disable FTP support unless explicitly required, as modern browsers (including Chromium-based ones) no longer support FTP, making legitimate proxy traffic rare.
### AI-Assisted Discovery
The flaw was identified using Claude Mythos Preview, which flagged the `strchr` null terminator behavior during an analysis of Squid’s FTP state machine. This follows a growing trend of AI-assisted security audits, with the team previously uncovering an HTTP/2 vulnerability using OpenAI’s Codex Cyber.
The discovery highlights how LLMs trained on C standards can detect subtle API contract violations that evade traditional code reviews.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SHPP ??
What was SHPP's A.I Rankiteo Cyber Score in August 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in July 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in June 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in May 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in April 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in March 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in February 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in January 2026 ??
What was SHPP's A.I Rankiteo Cyber Score in December 2025 ??
What was SHPP's A.I Rankiteo Cyber Score in November 2025 ??
What was SHPP's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on SHPP's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SHPP ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SHPP's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?