Back to Database
Status published
Medium
CVE-2024-37894
Squid vulnerable to heap corruption in ESI assign
Vulnerability Description
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37894
Credits & Attribution
No credits recorded in the NVD database.
References
More from squid-cache
View All →CVE-2025-62168
Squid vulnerable to information disclosure via authentication credential leakage in error handling
Critical
10
CVE-2025-54574
Squid's URN Handling can lead to Buffer Overflow
Critical
9.3
CVE-2024-45802
Squid Denial of Service
High
7.5
CVE-2024-25617
Denial of Service in HTTP Header parser in squid proxy
Medium
5.3
CVE-2024-25111
SQUID-2024:1 Denial of Service in HTTP Chunked Decoding
High
8.6
Affected Vendor
squid-cache
View all reports →Affected Software
squid
Vulnerable Versions:
>= 3.0, <= 3.5.28, >= 4.0, <= 4.16, >= 5.0, <= 5.9, >= 6.0, <= 6.9
Timeline
Official Publish:
June 25th, 2024
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H