CVE-2021-28651

Updated: 2026-02-27 00:16:01.67174

Description:

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CloudLinux 7 ELS squid 3.5.20 7.5 HIGH Released CLSA-2024:1733909428 2024-12-25 23:21:38
Debian 10 ELS squid 4.6.0 7.5 HIGH Already Fixed 2025-10-15 20:15:18
Oracle Linux 6 ELS squid 3.1.23 7.5 HIGH Released CLSA-2021:1634925537 2021-12-09 07:57:08
Oracle Linux 6 ELS squid34 3.4.14 7.5 HIGH Released CLSA-2021:1634925634 2021-12-09 07:57:08
Oracle Linux 7 ELS squid 3.5.20 7.5 HIGH Already Fixed 2024-12-10 16:21:56
RHEL 7 ELS squid 3.5.20 7.5 HIGH Released CLSA-2025:1757698482 2025-09-12 19:25:25
Ubuntu 16.04 ELS squid 3.5.12-1 7.5 HIGH Released CLSA-2021:1635459285 2021-12-09 07:57:08
Ubuntu 18.04 ELS squid 3.5.27-1 7.5 HIGH Already Fixed 2023-06-22 17:07:10
Ubuntu 20.04 ELS squid 4.10 7.5 HIGH Already Fixed 2025-09-11 21:27:10
Total: 19