[CLSA-2026:1777054556] squid: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-24 18:16:01 UTC
Description:
- CVE-2022-41317: fix exposure of sensitive cache manager information via non-HTTP URI schemes due to typo in default manager ACL regex - CVE-2023-49288: fix use-after-free in StoreEntry::startWriting() reachable via oversized replies with collapsed_forwarding enabled
Updated packages:
  • squid-5.5-19.el9_6.1.tuxcare.els5.x86_64.rpm
    sha:f6b02801c514d12cc478be372c6592ad01bbdb75ff0260e2a72411911b417d44
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.