← Back to CVE List
Vulnerability Intelligence Report
Squid vulnerable to information disclosure via authentication credential leakage in error handling

CVE-2025-62168

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Squid to be configured with HTTP authentication. The vulnerability is fixed in version 7.2. As a workaround, disable debug information in administrator mailto links generated by Squid by configuring squid.conf with email_err_data off.

Nuclei Template
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:5.8
EPSS Probability:63.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-209 ↗CWE-209: Generation of Error Message Containing Sensitive Information
CWE-550 ↗CWE-550: Server-generated Error Message Containing Sensitive Information

Affected Products & Versions

Vendor Product Affected Versions
squid-cache squid < 7.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
63.320%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2025-10-07T16:12:03
Published2025-10-17T16:21:30
Last Updated2026-02-26T16:57:24

LINK COPIED TO CLIPBOARD