A vulnerability that lets one person read another's traffic has been found in Squid, a widely used open-source proxy (a server that relays network traffic). Security firm Calif.io disclosed it in June and named it "Squidbleed" (CVE-2026-47729). The code responsible was written back in 1997 and had gone unnoticed for 29 years. What finally caught it was Claude, the AI model developed by Anthropic.

What Is "Squidbleed"

Squidbleed is a flaw that lets a party who should have no access read part of the memory Squid is using. The name echoes "Heartbleed," the 2014 vulnerability that leaked memory in much the same way.

What leaks is the traffic of another user going through the same Squid instance. For unencrypted HTTP traffic, that can include the passwords and session tokens (the credentials that keep you logged in) carried inside it. Technically, it is classified as a "heap over-read" (a bug that reads past the edge of a memory region the program has allocated).

It Started With a Single Line From 1997

The problem sat in the part of Squid that parses FTP (a file-transfer mechanism) directory listings. To cope with old machines that padded listings with extra spaces, the code skipped whitespace with a loop like this:

while (strchr(w_space, *copyFrom)) ++copyFrom;

If an attacker's FTP server returns a truncated listing line with no filename, the read position reaches the "null terminator" that marks the end of the string. strchr, the C string-search function, treats that terminator as part of the string it searches, so it returns a pointer instead of the NULL it should. The loop never stops, and reading runs off the end of the allocated memory.

Squid then sends that overrun region back to the attacker as a "filename." Because Squid reuses freed memory without clearing it, a region that just held another user's HTTP request is handed straight to the attacker.

The Conditions Required for an Attack

That said, it cannot be exploited by just anyone. The attacker has to be an insider already permitted to use the proxy. The main scenario is an environment where many people share a single proxy, such as a school, an office, or public Wi-Fi.

Only traffic Squid can actually read is exposed; ordinary HTTPS passes through as an encrypted tunnel and is out of scope. The attacker also needs to run an FTP server the proxy can reach. Both FTP and its port (21) are enabled in Squid's default configuration, so the conditions are hardly exotic.

The AI That Spotted a 29-Year-Old Oversight

The first to flag the bug was Anthropic's AI model "Claude Mythos Preview." Calif.io used the model in Project Glasswing, a defensive security research effort, to examine Squid's FTP handling, and it reportedly spotted the quirky strchr behavior almost immediately.

A single line that had slipped past 29 years of human code reviews and audits was found by an AI in short order. Similar "bugs buried in parsing code" are being turned up by AI in other software as well, including the video library FFmpeg, and Calif.io suggests Squid's FTP code may still hold more of the same.

Fixes and Severity

There are two ways to respond. One is to update Squid to a patched version. The fix itself is small, adding a null-terminator check before the problematic strchr calls; it landed in the development branch in April and in the official v7 line in May. Which version first carried the fix has flip-flopped even among the developers, so after updating it is safest to confirm the code is actually corrected rather than relying on the version number alone.

The other is simply to disable FTP. The major browser Chromium already dropped FTP support, and there is little occasion to use it today. The researchers recommend this route.

The severity is rated 6.5, "medium," on CVSS. An attack requires proxy access, and the impact is limited to information disclosure, with no tampering or service disruption. Proof-of-concept code is already public, but no real-world exploitation has been reported so far.

Summary

Squidbleed is a nasty flaw that exploits an oversight lurking for 29 years, even if the conditions to trigger it are limited. At the same time, the fact that an AI instantly caught a single line the human eye had missed for years drew attention in its own right, standing as a symbol of the growing use of AI in security research. If you run Squid, it is worth updating to the patched version, or disabling FTP if you do not need it.