Server-generated Error Message Containing Sensitive Information Affecting squid package, versions [,7.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.45% (63rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-generated Error Message Containing Sensitive Information vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-SQUID-13609896
  • published17 Oct 2025
  • disclosed17 Oct 2025
  • creditLeonardo Giovannini

Introduced: 17 Oct 2025

NewCVE-2025-62168  (opens in a new tab)
CWE-209  (opens in a new tab)
CWE-550  (opens in a new tab)

How to fix?

Upgrade squid to version 7.2 or higher.

Overview

Affected versions of this package are vulnerable to Server-generated Error Message Containing Sensitive Information via improper handling of HTTP authentication credentials in error responses of request_hdrs buffer. An attacker can obtain sensitive authentication information by triggering error conditions and analyzing the resulting responses. This is only exploitable if debug information in administrator mailto links is enabled in the configuration.

##Workaround

This vulnerability can be mitigated by disabling debug information in administrator mailto links by configuring squid.conf with email_err_data off.

CVSS Base Scores

version 4.0
version 3.1