{
    "id": "CVE-2020-15049",
    "published": "2020-06-30 18:15:12",
    "last_modified": "2026-06-17 02:55:57",
    "cvss_score": "9.9",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
    "cwe": "CWE-444",
    "description": "An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing \"+\\ \"-\" or an uncommon shell whitespace character prefix to the length field-value.",
    "epss_score": "0.05706",
    "epss_percentile": "0.92802",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-06 18:17:22",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.9), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "fedoraproject",
            "product": "fedora"
        },
        {
            "vendor": "squid-cache",
            "product": "squid"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00012.html",
        "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00017.html",
        "http://www.squid-cache.org/Versions/v4/changesets/squid-4-ea12a34d338b962707d5078d6d1fc7c6eb119a22.patch",
        "http://www.squid-cache.org/Versions/v5/changesets/squid-5-485c9a7bb1bba88754e07ad0094647ea57a6eb8d.patch",
        "https://github.com/squid-cache/squid/security/advisories/GHSA-qf3v-rc95-96j5",
        "https://lists.debian.org/debian-lts-announce/2020/10/msg00005.html",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3RG5FGSTCAYVIJPJHIY3MRZ7NFT6HDO7/",
        "https://security.netapp.com/advisory/ntap-20210312-0001/",
        "https://usn.ubuntu.com/4551-1/",
        "https://www.debian.org/security/2020/dsa-4732",
        "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00012.html",
        "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00017.html",
        "http://www.squid-cache.org/Versions/v4/changesets/squid-4-ea12a34d338b962707d5078d6d1fc7c6eb119a22.patch",
        "http://www.squid-cache.org/Versions/v5/changesets/squid-5-485c9a7bb1bba88754e07ad0094647ea57a6eb8d.patch",
        "https://github.com/squid-cache/squid/security/advisories/GHSA-qf3v-rc95-96j5",
        "https://lists.debian.org/debian-lts-announce/2020/10/msg00005.html",
        "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3RG5FGSTCAYVIJPJHIY3MRZ7NFT6HDO7/",
        "https://security.netapp.com/advisory/ntap-20210312-0001/",
        "https://usn.ubuntu.com/4551-1/",
        "https://www.debian.org/security/2020/dsa-4732"
    ]
}