Questions on Squid Version Detection / VTs (Squid Detection (HTTP))

Greenbone scanner reported multiple security vulnerabilities for Squid in Netgate Pfsense 2.7.2 fork. The installed version (squid 7.6) is flagged as vulnerable, despite listed vulnerabilities being closed in previous versions, listing Squid Multiple 0-Day Vulnerabilities (Oct 2023) (OID: 1.3.6.1.4.1.25623.1.0.900611) and CVE-2004-0189 FreeBSD Ports: squid (squid OID: 1.3.6.1.4.1.25623.1.0.52488) in the detection.

Could you please verify whether this is a false positive or if there is another explanation for this detection?

Squid Multiple 0-Day Vulnerabilities (Oct 2023). Squid is prone to multiple zero-day (0-day) vulnerabilities.

Details:
• Product: cpe:/a:squid-cache:squid
• Installed version: unknown
• Fixed version: None
• Path / port: 3128/tcp
• Scanner OID: 1.3.6.1.4.1.25623.1.0.900611
• Scan date: July 10, 2026
• Affected system: FreeBSD Pfsense

FreeBSD Ports: squid. The remote host is missing an update to the system as announced in the referenced advisory. Package squid version 7.6 is installed which is known to be vulnerable.
The following package is affected: squid CVE-2004-0189 The ‘%xx’ URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL (‘%00’) characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.

Details:
• FreeBSD Ports: squid OID: 1.3.6.1.4.1.25623.1.0.52488
• Installed version: Squid 7.6
• Fixed version: 2.5.STABLE5 and up
• Scan date: July 10, 2026
• Affected system: FreeBSD Pfsense

Thank you for your support!

Hello,

and welcome to this community forums. Only a few short notes:

  1. Most of the flaws addressed in “Squid Multiple 0-Day Vulnerabilities” (Correct OID for this is: 1.3.6.1.4.1.25623.1.0.100439) are not fixed in any Squid release so far based on all available current info (only a few have unclear status with possible fixes but no official advisories), see e.g.:
  2. The metadata of the Squid VT gives additional notes / hints to create possible overrides, please review the information already provided within carefully
  3. FreeBSD LSCs are (at least currently) unsupported, see NVT: FreeBSD Ports: net-snmp. FALSE POSITIVE - #2 by cfi for more background info
1 Like