Generated remediation guidance and an executive summary. No account required.
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.
Cite this page
CVE-2019-12519. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2019-12519
Use CWE-787, Squid-Cache vendor hub and Squid product page to widen CVE-2019-12519 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-62168, CVE-2025-54574 and CVE-2026-33526 for nearby disclosures in the same product family.