CVE-2025-54574

Source
https://cve.org/CVERecord?id=CVE-2025-54574
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-54574.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-54574
Aliases
  • GHSA-w4gv-vw3f-29g3
Downstream
Published
2025-08-01T18:02:19.117Z
Modified
2026-05-15T04:14:04.694630419Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H CVSS Calculator
Summary
Squid's URN Handling can lead to Buffer Overflow
Details

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54574.json"
}
References

Affected packages