Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Affecting squid package, versions [2.6,6.4)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
2.48% (90th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SQUID-6037646
  • published27 Oct 2023
  • disclosed19 Oct 2023
  • creditKeran Mu, Jianjun Chen

Introduced: 19 Oct 2023

CVE-2023-46846  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

Upgrade squid to version 6.4 or higher.

Overview

Affected versions of this package are vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') through the HTTP/1.1 and ICAP protocols. An attacker can manipulate the sequence of requests and responses, potentially leading to unauthorized access or information disclosure.

Workaround

This vulnerability can be mitigated by ensuring only trusted ICAP services are used, with TLS encrypted connections (ICAPS extension).

There is no workaround for the HTTP Request Smuggling issue.

CVSS Scores

version 3.1