CVE-2026-47729

Source
https://cve.org/CVERecord?id=CVE-2026-47729
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47729.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47729
Aliases
  • GHSA-8c37-pxjq-qwrg
Downstream
Published
2026-07-16T16:13:19.767Z
Modified
2026-07-22T04:19:30.482586Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Squid: Memory disclosure in FTP gateway
Details

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47729.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-125",
        "CWE-1289"
    ]
}
References

Affected packages

Git / github.com/squid-cache/squid

Affected ranges

Type
GIT
Repo
https://github.com/squid-cache/squid
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.6"
        }
    ]
}

Affected versions

4.*
4.15-20210522-snapshot
4.15-20210523-snapshot
4.15-20210524-snapshot
4.15-20210525-snapshot
4.15-20210527-snapshot
5.*
5.0.6-20210522-snapshot
5.0.6-20210523-snapshot
5.0.6-20210524-snapshot
5.0.6-20210525-snapshot
5.0.6-20210527-snapshot
6.*
6.0.0-20210522-master-snapshot
6.0.0-20210523-master-snapshot
6.0.0-20210524-master-snapshot
6.0.0-20210525-master-snapshot
6.0.0-20210527-master-snapshot
Other
HISTORIC_RELEASES
M-staged-PR161
M-staged-PR164
M-staged-PR170
M-staged-PR176
M-staged-PR179
M-staged-PR181
M-staged-PR182
M-staged-PR186
M-staged-PR189
M-staged-PR193
M-staged-PR195
M-staged-PR196
M-staged-PR198
M-staged-PR199
M-staged-PR200
M-staged-PR202
M-staged-PR206
M-staged-PR208
M-staged-PR209
M-staged-PR210
M-staged-PR218
M-staged-PR220
M-staged-PR221
M-staged-PR225
M-staged-PR227
M-staged-PR229
M-staged-PR230
M-staged-PR235
M-staged-PR237
M-staged-PR238
M-staged-PR239
M-staged-PR241
M-staged-PR242
M-staged-PR252
M-staged-PR255
M-staged-PR258
M-staged-PR264
M-staged-PR266
M-staged-PR267
M-staged-PR268
M-staged-PR274
M-staged-PR276
M-staged-PR293
M-staged-PR294
M-staged-PR295
M-staged-PR299
M-staged-PR306
M-staged-PR314
M-staged-PR319
M-staged-PR342
M-staged-PR345
M-staged-PR348
M-staged-PR351
M-staged-PR359
M-staged-PR364
M-staged-PR365
M-staged-PR366
M-staged-PR370
M-staged-PR372
M-staged-PR373
M-staged-PR375
M-staged-PR376
SQUID_3_0_PRE1
SQUID_3_0_PRE2
SQUID_3_0_PRE3
SQUID_3_0_PRE4
SQUID_3_0_PRE5
SQUID_3_0_PRE6
SQUID_3_0_PRE7
SQUID_3_0_RC1
SQUID_3_5_27
SQUID_4_0_1
SQUID_4_0_10
SQUID_4_0_11
SQUID_4_0_12
SQUID_4_0_13
SQUID_4_0_14
SQUID_4_0_15
SQUID_4_0_16
SQUID_4_0_2
SQUID_4_0_3
SQUID_4_0_4
SQUID_4_0_5
SQUID_4_0_6
SQUID_4_0_7
SQUID_4_0_8
SQUID_4_0_9
SQUID_7_0_1
SQUID_7_0_2
SQUID_7_1
SQUID_7_2
SQUID_7_3
SQUID_7_4
SQUID_7_5
take00

Database specific

vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "200485499472286574017853506929422920067",
                "205052801346471324740146741138928613476",
                "33954367451075217029817620006087162873",
                "107747331627736500759657556035124122214",
                "288086731375907134233604495937464541764",
                "109929495246555111575859274533938701343",
                "290867259214494210862351622144020694715"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8",
        "signature_type": "Line",
        "target": {
            "file": "src/clients/FtpGateway.cc"
        },
        "id": "CVE-2026-47729-28deeb07",
        "deprecated": false
    },
    {
        "digest": {
            "length": 4189.0,
            "function_hash": "312956656738982574512693199906401205765"
        },
        "signature_version": "v1",
        "source": "https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8",
        "signature_type": "Function",
        "target": {
            "function": "ftpListParseParts",
            "file": "src/clients/FtpGateway.cc"
        },
        "id": "CVE-2026-47729-5b8031f2",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-22T04:19:30Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47729.json"