{"id":"AZL-92447","summary":"CVE-2026-50012 affecting package squid for versions less than 6.13-5","details":"Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the mask_size declared within the digest, so a trusted peer sending a maliciously crafted reply to a cache_digest request message can trigger the overflow. This attack is limited to Squid instances compiled with the --enable-cache-digests option and configured with cache_peer entries. This issue is fixed in version 7.6.","modified":"2026-09-03T05:27:10Z","published":"2026-07-16T17:16:57Z","upstream":["CVE-2026-50012"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50012"}],"affected":[{"package":{"name":"squid","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/squid"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.13-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92447.json"}}],"schema_version":"1.9.0"}