VDB
ALPINE-CVE-2016-10003
ALPINE-CVE-2016-10003
PUBLISHED
CVSS 7.5 HIGH
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.2 | squid | 0, 2.7.6-r0, 2.7.6-r10 |
| Alpine:v3.3 | squid | 3.3.9-r0, 3.5.18-r1, 3.5.3-r0 |
Timeline
- Jan 27, 2017 CVE Published
- Nov 19, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch