CVE-2026-32748

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*

History

26 Mar 2026, 20:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
First Time Squid-cache squid
Squid-cache
Summary
  • (es) Squid es un proxy de almacenamiento en caché para la Web. Antes de la versión 7.5, debido a la liberación prematura de recursos durante la vida útil esperada y errores de uso después de liberación en el heap, Squid es vulnerable a denegación de servicio al manejar tráfico ICP. Este problema permite a un atacante remoto realizar un ataque de denegación de servicio fiable y repetible contra el servicio Squid usando el protocolo ICP. Este ataque está limitado a despliegues de Squid que habilitan explícitamente el soporte ICP (es decir, configurar un 'icp_port' distinto de cero). Este problema _no puede_ ser mitigado denegando consultas ICP usando reglas de 'icp_access'. Este error está corregido en la versión 7.5 de Squid.
References () https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b - () https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b - Patch
References () https://github.com/squid-cache/squid/security/advisories/GHSA-f9p7-3jqg-hhvq - () https://github.com/squid-cache/squid/security/advisories/GHSA-f9p7-3jqg-hhvq - Mitigation, Patch, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/03/25/3 - () http://www.openwall.com/lists/oss-security/2026/03/25/3 - Mailing List, Patch, Third Party Advisory, Mitigation

26 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 01:16

Updated : 2026-03-26 20:43


NVD link : CVE-2026-32748

Mitre link : CVE-2026-32748

CVE.ORG link : CVE-2026-32748


JSON object : View

Products Affected

squid-cache

  • squid
CWE
CWE-413

Improper Resource Locking

CWE-416

Use After Free

CWE-826

Premature Release of Resource During Expected Lifetime