@xsser往squid的mailing-list发过邮件后,刚刚收到了回复Thank you for the report. We have been aware of the problem for some time and have already fixed two aspects of it in the currently supported Squid versions.All of the recent releases should be responding to blocked methods with "405 Method Not Allowed" which error page does not contain any of the headers.NP: Thank you for highlighting that % code is not being permitted when it should be, that is a regular bug.Other ways of getting the "400 Bad Request" error page with header snippets in current releases having their HTTP security credentials elided. Headers such as Cookie are not supposed to be containing any sensitive information as they are vulnerable to cross-site delivery, replication, replay, caching. It is a systemic vulnerability to send sensitive information in such headers. We can take no responsibility for such brokenness in website code, nor is it practical to have Squid dig down into such headers and guess at what may or may not be sensitive.If you are aware of a site still using Squid-2.7 and squid-3.1, please advise them they are vulnerable to this and several other far more major security vulnerabilities.Cheers看来最新的release已经修正了一部分问题是不是算已经认领?