Description
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Use After Free Vulnerability (CVE-2019-0211)
OpenSSL Numeric Errors Vulnerability (CVE-2009-0789)
Liferay DXP Missing Authorization Vulnerability (CVE-2025-43773)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1159)
XWikiplatform Missing Authorization Vulnerability (CVE-2024-55879)