You may have heard about Squidbleed (aka CVE-2026-47729). It has the classic hallmarks of a headline-grabbing security issue: a catchy name, a legacy protocol (FTP), and a potential for data leakage. But before you initiate emergency procedures, let’s take a breath and look at the reality of this vulnerability.

Why you (probably) don’t need to panic #

While any vulnerability disclosure deserves attention, the actual exploitability of CVE-2026-47729 is highly situational. Here is why this likely isn't the "sky is falling" moment some might fear:

  • HTTPS is the usual default: Most modern web traffic is encrypted via HTTPS. When Squid handles this, it typically uses an opaque CONNECT tunnel, rendering the contents of that traffic encrypted, even in the case of a successful exploit.

  • The FTP requirement: The vulnerability is specifically tied to FTP (File Transfer Protocol). For an attack to work, the proxy must be directed to an attacker-controlled FTP server on 21/TCP that’s specially created to exploit the FTP LIST condition.

  • Deployment matters: This attack pattern described by Calif assumes a level of "open proxy" access that is rarely how Squid is deployed in production environments. Most implementations are configured to sit between internal clients and the internet, not as an open gateway for anyone to come calling. This reality limits your attacker-space to mostly insiders.

Why you should still check #

So, if it’s so situational, why is it making noise?

  • It’s legacy: FTP is still alive and well in state and federal environments and in many education environments, where old-style FTP is frequently used to move files. It’s not super-unusual, even today.

  • It’s bundled: Squid is often shipped as a proprietary or niche proxy solution. You might be running it without realizing it.

  • It’s an info leak: At its core, this is an information disclosure vulnerability that risks some secrets, in some circumstances, like passwords, session tokens, and API keys. If an attacker does manage to trick an internal user into using your proxy to connect to their malicious FTP server, the attack may be worthwhile.

How to find Squid Proxy on your network #

All that said, it’s pretty easy to take a quick audit of your environment for Squid proxy, and see if there are any surprises, or double-check your patch levels. You can use the following software query in runZero to identify assets running Squid.

vendor:="Squid Cache" AND product:=Squid AND (version:>0 AND version:<7.6)

The bottom line #

The bug has been patched since April 8. If you (or your Linux distribution, or your proprietary proxy vendor) are very on top of your routine Squid proxy patching (without the benefit of a flashy CVE), you would have picked up the patch normally. While it’s worth verifying where your internal instances are, this vulnerability requires a level of attacker interaction and specific network architecture that makes it less of a "drive-by" threat and more of an edge case. In other words, no need to panic about this, but it’s worth a second look at your services inventory.

Written by todb

Tod Beardsley is VP of Security Research at runZero, where he "kicks assets and fakes frames." Prior to 2025, he was the Section Chief for the Vulnerability Response section for CSD/VM/VRC at CISA, the Cybersecurity and Infrastructure Security Agency, part of the US government, and a seasonal Travis County Election Judge in Texas. He's also a founder and CNA point of contact for AHA!. Tod spends much of his time involved in vulnerability research and coordinated vulnerability disclosure (CVD). He has over 30 years of hands-on security experience, stretching from in-band telephony switching to modern ICS/OT implementations. He has held IT ops, security, software engineering, and management positions in large organizations such as the US Government, Rapid7, 3Com, Dell, and Westinghouse, as both an offensive and defensive practitioner. Tod is a CVE Board member, has authored several research papers, and is an internationally-tolerated horror fiction expert.

More about todb
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...
Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.