29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

Squidbleed CVE-2026-47729 can expose cleartext HTTP credentials from users sharing the same Squid proxy.

The Hacker News
@thenewoil Oh no! Are you saying that attackers could read requests not sent under TLS? Wait ... attackers have always been able to read requests not sent under TLS.