Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47729.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125",
"CWE-1289"
]
}{
"cpe": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.6"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"200485499472286574017853506929422920067",
"205052801346471324740146741138928613476",
"33954367451075217029817620006087162873",
"107747331627736500759657556035124122214",
"288086731375907134233604495937464541764",
"109929495246555111575859274533938701343",
"290867259214494210862351622144020694715"
]
},
"signature_version": "v1",
"source": "https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8",
"signature_type": "Line",
"target": {
"file": "src/clients/FtpGateway.cc"
},
"id": "CVE-2026-47729-28deeb07",
"deprecated": false
},
{
"digest": {
"length": 4189.0,
"function_hash": "312956656738982574512693199906401205765"
},
"signature_version": "v1",
"source": "https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8",
"signature_type": "Function",
"target": {
"function": "ftpListParseParts",
"file": "src/clients/FtpGateway.cc"
},
"id": "CVE-2026-47729-5b8031f2",
"deprecated": false
}
]
"2026-07-22T04:19:30Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47729.json"