Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92444.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92444
Upstream
Published
2026-07-16T17:16:57Z
Modified
2026-09-03T05:27:10Z
Summary
CVE-2026-47729 affecting package squid for versions less than 6.13-5
Details

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.

References

Affected packages

Azure Linux:3 / squid

Package

Name
squid
Purl
pkg:rpm/azure-linux/squid

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.13-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92444.json"