NIXPKGS-2025-0018
published on 26 Sep 2025
by @Erethon Activity log
- Created automatic suggestion
- @Erethon accepted
- @Erethon published on GitHub
Squid: dos against http and https
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
Affected products
squid
- ==6.4
- *
squid:4
- *
Matching in nixpkgs
pkgs.squid
Caching proxy for the Web supporting HTTP, HTTPS, FTP, and more
-
nixos-25.05 -
- nixos-25.05-small 7.0.1
Package maintainers
-
@srhb Sarah Brofeldt <sbrofeldt@gmail.com>
-
@happysalada Raphael Megzari <raphael@megzari.com>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>