References https://nvd.nist.gov/vuln/detail/cve-2023-46847 https://cve.imfht.com/detail/CVE-2023-46847 https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g https://access.redhat.com/security/cve/cve-2023-46847 https://www.sentinelone.com/vulnerability-database/cve-2023-46847/ https://www.fortiguard.com/encyclopedia/ips/54508 https://dbugs.ptsecurity.com/vulnerability/PT-2023-6902 https://bugs.gentoo.org/show_bug.cgi?format=multiple&id=916334 https://linuxsoft.cern.ch/cern/centos/7/updates/x86_64/repoview/squid.html https://www.tenable.com/plugins/nessus/239315
Related VulnerabilitiesPoCCVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp ProxyPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCCVE-2025-26399: SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCELobeChat /webapi/proxy 服务器端请求伪造漏洞(CVE-2026-54157)东胜物流软件 /PriceCarrier/CrmProxyMailListHtmlGridSource.aspx SQL 注入漏洞关于用友GRP-U8Cloud产品getBudgetReleaseProjectList及U8AppProxy及fbpm-modeler存在命令执行漏洞的安全通告Apache Druid /proxy/coordinator@ 服务器端请求伪造漏洞(CVE-2025-27888)Apache HTTP/2 双重释放漏洞(CVE-2026-23918)Gradio /proxy 服务器端请求伪造漏洞(CVE-2023-34239)PoCCVE-2025-62168: Squid Proxy - HTTP Authentication Credentials DisclosurePoClitellm-unauth-model-exposure: LiteLLM Proxy - Model ExposurePoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorArtica Proxy /images.listener.php 文件读取漏洞(CVE-2024-2053)