Greenbone scanner reported multiple security vulnerabilities for Squid in Netgate Pfsense 2.7.2 fork. The installed version (squid 7.6) is flagged as vulnerable, despite listed vulnerabilities being closed in previous versions, listing Squid Multiple 0-Day Vulnerabilities (Oct 2023) (OID: 1.3.6.1.4.1.25623.1.0.900611) and CVE-2004-0189 FreeBSD Ports: squid (squid OID: 1.3.6.1.4.1.25623.1.0.52488) in the detection.
Could you please verify whether this is a false positive or if there is another explanation for this detection?
Squid Multiple 0-Day Vulnerabilities (Oct 2023). Squid is prone to multiple zero-day (0-day) vulnerabilities.
Details:
• Product: cpe:/a:squid-cache:squid
• Installed version: unknown
• Fixed version: None
• Path / port: 3128/tcp
• Scanner OID: 1.3.6.1.4.1.25623.1.0.900611
• Scan date: July 10, 2026
• Affected system: FreeBSD Pfsense
FreeBSD Ports: squid. The remote host is missing an update to the system as announced in the referenced advisory. Package squid version 7.6 is installed which is known to be vulnerable.
The following package is affected: squid CVE-2004-0189 The ‘%xx’ URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL (‘%00’) characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.
Details:
• FreeBSD Ports: squid OID: 1.3.6.1.4.1.25623.1.0.52488
• Installed version: Squid 7.6
• Fixed version: 2.5.STABLE5 and up
• Scan date: July 10, 2026
• Affected system: FreeBSD Pfsense
Thank you for your support!