cvedb.io
CVE-2023-46847
HIGH · CVSS 8.6
EPSS exploitation probability: 0%
Published 2023-11-03T08:15:08.023 · Last modified 2026-08-07T02:16:30.157

Summary

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

Affected products

squid-cache — squid

Does this affect you?

Add your gear to cvedb and we'll alert you only when squid-cache ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.