Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilitycredential-access-methodperimeter-device-exposure

Critical Information Disclosure Vulnerability in Squid Proxy via Error Handling (CVE-2025-62168)

Updated 3mo agoFirst seen Oct 20, 20252 sources

A critical vulnerability, tracked as CVE-2025-62168, has been identified in Squid, a widely used web caching proxy. This flaw, which carries a maximum CVSS score of 10.0, allows for the leakage of HTTP authentication credentials and security tokens through improper error handling. The vulnerability affects all Squid versions prior to 7.2, where a failure to redact sensitive information in error messages can result in information disclosure. Attackers can exploit this issue remotely, enabling them to bypass browser security protections and obtain credentials used by trusted clients. The vulnerability does not require Squid to be configured with HTTP authentication, broadening the potential attack surface. Scripts can leverage this flaw to extract credentials or security tokens that are used internally by web applications relying on Squid for backend load balancing. The risk is particularly severe for organizations using Squid as a reverse proxy or in environments where sensitive authentication data is transmitted. The vulnerability was disclosed publicly in October 2025, with security advisories highlighting the ease of remote exploitation. Administrators are urged to upgrade to Squid version 7.2, which contains the necessary fix to address this issue. As a temporary mitigation, disabling debug information in administrator mailto links by setting 'email_err_data off' in the squid.conf configuration file is recommended. The vulnerability's critical rating underscores the urgency for immediate remediation to prevent potential credential theft and unauthorized access. Security researchers emphasize that the flaw could be used in targeted attacks against organizations with exposed Squid proxies. The issue was reported through security advisories and has been acknowledged by the Squid development team. Organizations are advised to review their proxy configurations and apply the patch as soon as possible. The vulnerability highlights the importance of proper error handling and redaction of sensitive data in security-critical infrastructure. Failure to address this flaw could result in significant data breaches or compromise of internal systems. The disclosure has prompted widespread attention in the cybersecurity community, with multiple advisories and technical analyses published to assist defenders. The incident serves as a reminder of the risks associated with misconfigured or outdated proxy services in enterprise environments.

Share:
Critical Information Disclosure Vulnerability in Squid Proxy via Error Handling (CVE-2025-62168)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Oct 17, 20258mo ago

Workaround documented for credential leakage flaw

Alongside disclosure of CVE-2025-62168, a mitigation was documented for affected deployments: disable debug information in administrator mailto links by setting "email_err_data off" in squid.conf. The workaround reduces exposure for versions prior to 7.2.

Squid fixes CVE-2025-62168 in version 7.2

Squid addressed a critical information disclosure flaw, CVE-2025-62168, in version 7.2. The bug allowed HTTP authentication credentials and internal security tokens to leak through error handling when credentials were not properly redacted.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Affected products
2 linked
SquidSquid
Organizations
1 linked
Squid-Cache
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.