CVE-2023-46846
9.3
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.3), but no sign of active exploitation.
Description
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
Scoring
| CVSS | 9.3 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
| EPSS | 6.21% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-444 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-11-03 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| redhat | enterprise linux |
| redhat | enterprise linux eus |
| redhat | enterprise linux for arm 64 |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for power little endian |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server tus |
| squid-cache | squid |
References
- https://access.redhat.com/errata/RHSA-2023:6266
- https://access.redhat.com/errata/RHSA-2023:6267
- https://access.redhat.com/errata/RHSA-2023:6268
- https://access.redhat.com/errata/RHSA-2023:6748
- https://access.redhat.com/errata/RHSA-2023:6801
- https://access.redhat.com/errata/RHSA-2023:6803
- https://access.redhat.com/errata/RHSA-2023:6804
- https://access.redhat.com/errata/RHSA-2023:6810
- https://access.redhat.com/errata/RHSA-2023:7213
- https://access.redhat.com/errata/RHSA-2024:11049
- https://access.redhat.com/security/cve/CVE-2023-46846
- https://bugzilla.redhat.com/show_bug.cgi?id=2245910
- https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh
- https://access.redhat.com/errata/RHSA-2023:6266
- https://access.redhat.com/errata/RHSA-2023:6267
- https://access.redhat.com/errata/RHSA-2023:6268
- https://access.redhat.com/errata/RHSA-2023:6748
- https://access.redhat.com/errata/RHSA-2023:6801
- https://access.redhat.com/errata/RHSA-2023:6803
- https://access.redhat.com/errata/RHSA-2023:6804
→ the Explorer · watch your stack · NVD