Squidbleed (CVE-2026-47729) is an out-of-bounds read vulnerability in Squid's FTP gateway directory-listing parser, located in src/clients/FtpGateway.cc. In Squid versions before 7.6, improper validation of a TypeA or TypeB FTP listing entry can allow parsing to continue beyond the input buffer when a date is not followed by a filename. A trusted proxy client accessing a misbehaving FTP server through the gateway can receive memory from unrelated proxy transactions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact standalone proof-of-concept exploit for CVE-2026-47729 ('Squidbleed'), targeting Squid's FTP handling to trigger an information disclosure condition. The repository contains only two files: a README and a single Python exploit script, making CVE-2026-47729.py the clear entry point. The exploit has two tightly integrated components in one script. First, it starts an attacker-controlled FTP server that emulates enough FTP behavior to satisfy a client: USER/PASS, SYST, PWD, TYPE, EPSV, LIST/NLST, and QUIT. The key malicious behavior is in the LIST/NLST handling, where it sends a crafted truncated directory listing line and closes the data connection, intended to trigger the vulnerable memory over-read behavior in Squid. Second, the script acts as a poller/harvester against a target Squid proxy. It repeatedly opens a TCP connection to the configured proxy (default 127.0.0.1:3128) and sends an HTTP GET request for an ftp:// URL pointing to the attacker FTP server (default ftp://anon:x@127.0.0.1:2222/). It then reads the proxy response body and searches for leaked data embedded in HTML href content. The script URL-decodes the leaked bytes and applies regex extraction for Basic and Bearer tokens. Basic tokens are additionally Base64-decoded and printed as username:password when possible. Operationally, the exploit is multithreaded: one background thread runs the FTP server, multiple worker threads continuously poll the proxy, and a status thread reports polling rate, hit count, and distinct token counts. This is not merely a detector; it actively attempts exploitation and harvests sensitive material from leaked memory. There is no post-exploitation shell or code execution payload—its purpose is credential and token disclosure from a vulnerable Squid instance.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
108 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability referenced by an AlmaLinux 9.2 TuxCare local security-check plugin. The content supplies no technical description or impact details specific to this CVE.
A specific vulnerability referenced by a Rocky Linux 9.6 local security advisory; no technical flaw description is provided.
A vulnerability addressed by the referenced TuxCare CentOS 6 security advisory; no technical flaw description is provided.
A Squid vulnerability cited as an example of shared attribution across multiple AI-assisted discovery paths; no technical details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.