vulnerability 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A 29-year-old vulnerability, dubbed Squidbleed (CVE-2026-47729), exists in the Squid web proxy due to a heap over-read. This allows an attacker with proxy access to leak cleartext HTTP requests, including credentials and session tokens, by exploiting a flawed FTP parsing mechanism. While no in-the-wild exploitation has… The Hacker News · Jun 22, 2026 Medium CVE-2026-47729CVE-2026-50012heap_overflowhttpftp