Skip to main content

CVE-2016-4554

8.6
HIGHCVSS v3.1 Base Score
68.86%
MEDIUM RiskEPSS (99th percentile)

mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

Published: 5/10/2016
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

EPSS Score (Exploitation Probability)

68.86%MEDIUM Exploitation Risk
99th percentile

This vulnerability has a 68.86% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

Related Vulnerabilities