A heap over-read in the Squid web proxy can leak another
user's cleartext HTTP request, including any credentials or session
tokens it carries, to anyone already allowed to send traffic
through the same proxy. The bug traces to a 1997 FTP-parsing change
and is still live in Squid's default configuration. Researchers at
Calif.io disclosed it in June and named it Squidbleed
(
Read more https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html

