Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors. https://nvd.nist.gov/vuln/detail/CVE-2018-19131