Squidbleed (CVE-2026-47729): Claude Mythos Found a 29-Year-Old Heartbleed-Style Memory Leak in Every Version of Squid Proxy — And the Patch Isn’t in 7.6
Squidbleed (CVE-2026-47729) is a Heartbleed-style heap buffer overread in Squid Proxy’s FTP directory listing parser that has lived in every version of Squid since 1997 — 29 years — in its default configuration. It leaks adjacent heap memory, potentially including other users’ HTTP Authorization headers, cookies, and session tokens. Discovered by Calif.io using Claude Mythos Preview. Critical correction: the patch is in Squid 7.7, NOT 7.6. Immediate mitigation: disable FTP in Squid. PoC is public.
