{"id":"CLSA-2026-1776879277","summary":"squid: Fix of 13 CVEs","details":"- CVE-2018-1000027: fix NULL pointer dereference in\n  clientFollowXForwardedForCheck for transactions without a client connection\n- CVE-2018-19131: fix XSS via X.509 certificate fields rendered unescaped in\n  SSL error pages\n- CVE-2019-12520: prevent cache poisoning by suppressing URL userinfo from\n  absolute URLs for non-FTP schemes\n- CVE-2019-12523: reject URIs with invalid scheme (non-alpha first char) and\n  malformed URN NID\n- CVE-2019-12526: add Must() guard in URN response handling to prevent\n  re-entry with zero-length buffer\n- CVE-2019-12528: fix FTP directory listing parser info leak from heap into\n  HTTP responses\n- CVE-2019-12529: fix Basic auth uudecode out-of-bounds read/write via proper\n  bounds checking\n- CVE-2019-13345: fix multiple XSS issues in cachemgr.cgi via rfc1738-escaping\n  user_name and auth parameters\n- CVE-2019-18676: cap URI scheme length and reject malformed scheme prefixes\n  to prevent buffer overflow in urlParse\n- CVE-2019-18677: prevent CSRF via append_domain truncation by rejecting\n  oversized domain appends\n- CVE-2019-18678: reject HTTP headers with whitespace between field-name and\n  colon per RFC 7230 to prevent request splitting\n- CVE-2019-18679: remove raw heap pointer from Digest nonce hash input to\n  prevent information disclosure and ASLR bypass\n- CVE-2019-18860: fix cachemgr.cgi XSS/info-disclosure via hostname parameter\n  validation","modified":"2026-05-27T11:18:03.845657816Z","published":"2026-04-23T18:38:25Z","upstream":["CVE-2018-1000027","CVE-2018-19131","CVE-2019-12520","CVE-2019-12523","CVE-2019-12526","CVE-2019-12528","CVE-2019-12529","CVE-2019-13345","CVE-2019-18676","CVE-2019-18677","CVE-2019-18678","CVE-2019-18679","CVE-2019-18860"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/oraclelinux6els/CLSA-2026-1776879277.html"}],"affected":[{"package":{"name":"squid","ecosystem":"TuxCare:OracleLinux:6","purl":"pkg:rpm/tuxcare/squid?distro=oraclelinux-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7:3.1.23-30.el6.tuxcare.els17"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux6els/CLSA-2026-1776879277.json"}}],"schema_version":"1.7.5"}