{"id":"AZL-92444","summary":"CVE-2026-47729 affecting package squid for versions less than 6.13-5","details":"Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.","modified":"2026-09-03T05:27:10Z","published":"2026-07-16T17:16:57Z","upstream":["CVE-2026-47729"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47729"}],"affected":[{"package":{"name":"squid","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/squid"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.13-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92444.json"}}],"schema_version":"1.9.0"}