Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peerdigest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the masksize declared within the digest, so a trusted peer sending a maliciously crafted reply to a cachedigest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cachepeer entries. This issue is fixed in version 7.6.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-122",
"CWE-20"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50012.json"
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.6"
}
]
}"2026-07-22T04:19:30Z"
[
{
"target": {
"file": "src/peer_digest.cc"
},
"digest": {
"line_hashes": [
"229550311145704481924451770564358024578",
"221920238537344078225207842802955983578",
"166847730665289552997050079606109205227"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-50012-8204a6ea",
"source": "https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd"
},
{
"target": {
"function": "peerDigestSwapInMask",
"file": "src/peer_digest.cc"
},
"digest": {
"length": 725.0,
"function_hash": "250827425887602908147261629380683058993"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-50012-839f3062",
"source": "https://github.com/squid-cache/squid/commit/19fcfe922717c8b255270c032dcde4071c003bcd"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50012.json"