CVE-2016-10003
7.5
HIGH
CVSS 3.1
EPSS 0.72%
Description
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
How to fix CVE-2016-10003
To remediate CVE-2016-10003, upgrade the affected package to a fixed version below.
- Alpine/squid—upgrade to 3.5.23-r0 or later
Is CVE-2016-10003 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.5.23-r0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |