CVE-2023-46846: Squid: request/response smuggling in http/1.1 and icap
Description: Due to chunked decoder lenience Squid is vulnerable to Request/Response smuggling attacks when parsing HTTP/1.1 and ICAP messages
Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh
Affected versions: 2.6-6.3. Patched in 6.4.
Other sources
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-46846?
CVE-2023-46846 is a vulnerability in Squid that allows a remote attacker to perform HTTP request smuggling past firewall and frontend security systems.
How severe is CVE-2023-46846?
CVE-2023-46846 has a severity rating of 9.3 (Critical).
How can I fix CVE-2023-46846?
To fix CVE-2023-46846, update your Squid software to version 6.4 or later.
Which software versions are affected by CVE-2023-46846?
Squid versions up to 6.4 are affected by CVE-2023-46846.
Where can I find more information about CVE-2023-46846?
You can find more information about CVE-2023-46846 on the Redhat advisory page: [link](https://access.redhat.com/errata/RHSA-2023:6266).