CVE-2026-47729: Squid: Memory disclosure in FTP gateway
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.13-5 - Upgrade
Upgrade
Squidto a version that resolves this vulnerability.Fixed in 7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-47729 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-50012
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47729?
CVE-2026-47729 has been rated with a high severity level due to its potential to compromise system integrity and security.
What are the main impacts of CVE-2026-47729?
CVE-2026-47729 could allow an attacker to exploit the vulnerability for unauthorized data access or service disruption.
How do I fix CVE-2026-47729?
To fix CVE-2026-47729, update your Squid software to the latest version provided by the maintainers.
Is there an exploit available for CVE-2026-47729?
Yes, there are known exploits for CVE-2026-47729 that target vulnerable versions of Squid.
When was CVE-2026-47729 published?
CVE-2026-47729 was published on June 12, 2026.