Skip to main content
Mallory
Unrated

Out-of-bounds Read in Squid FTP Gateway

IdentifiersCVE-2026-47729CWE-1287

CVE-2026-47729 is an out-of-bounds read vulnerability in Squid's FTP gateway caused by improper validation of the syntactic correctness of input. When a trusted client accesses a misbehaving FTP server through Squid's gateway feature, malformed or unexpected FTP input can cause Squid to read beyond intended bounds and disclose data from random unrelated transactions resident in memory. The issue affects the FTP gateway processing path; a referenced fix was published in Squid commit 865a131c7d557e68c965043d98c2eccae26deef8, and available reporting indicates the fix is intended for Squid 7.7.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can expose memory contents associated with unrelated proxy transactions, resulting in unintended disclosure of sensitive data from other sessions handled by the Squid process. Based on the provided information, the primary impact is information disclosure rather than code execution or integrity compromise.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by disabling or avoiding use of Squid's FTP gateway feature, restricting which clients are permitted to use the proxy for FTP access, and limiting or blocking access from Squid to untrusted or misbehaving FTP servers. Additional compensating controls include network ACLs and proxy policy restrictions that prevent trusted clients from reaching attacker-controlled FTP endpoints through the gateway.

Remediation

Patch, then assume compromise.

Upgrade Squid to a version containing the vendor fix for CVE-2026-47729. The provided content indicates the patch is associated with commit 865a131c7d557e68c965043d98c2eccae26deef8 and that the fix is expected in Squid 7.7. Apply the official vendor release that includes this patch rather than relying on unpatched 7.6 deployments.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.