5 Comments
User's avatar
Nelson C's avatar

The official Revision history:

https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg

Revision history:

2026-03-04 12:41:54 UTC Initial Report by Pavel Kohout of Aisle Research

2026-04-17: Initial Report by Lam Jun Rong

2026-05-07: Initial Report by Youssef Awad

2026-05-17 06:04:47 UTC patch published

Why did you leave out one? :D

Calif's avatar

We've updated the blog post.

Aisle was omitted from the draft advisory shared by the Squid team on 2026-06-08. The acknowledgement was subsequently added on 2026-06-12.

Calif's avatar

No, we did not leave them out.

The AISLE acknowledgement wasn't in the advisory draft the Squid team shared with us. They might add it recently after this blog post went live. We've reached out to Squid for more information, and will update the blog post once we've learned more of what happened.

Cecco Montone's avatar

Hasn't AI proof-read this article, because it says "40 May 20 04:17" in the transcript of the FTP directory listing? :)

Calif's avatar

The number 40 is the file size in bytes. Told ya that this format is hard to parse, didn't we?