CVE-2026-32748 Details
Description
Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.
A denial-of-service vulnerability has been identified in Squid versions prior to 7.5. This issue arises from a premature release of resources during their expected lifespan, combined with heap use-after-free bugs, leading to a reliable and repeatable denial-of-service condition when processing Internet Cache Protocol (ICP) traffic. The vulnerability affects Squid deployments that have ICP support enabled, specifically those configured with a non-zero 'icp_port'. Notably, this issue cannot be mitigated by denying ICP queries through 'icp_access' rules.
Users can upgrade to Squid version 7.5, where this vulnerability has been fixed. For those using prepackaged versions of Squid, refer to the package vendor for availability information on the updated version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-413 | Improper Resource Locking | [email protected] |
| CWE-416 | Use After Free | [email protected] |
| CWE-826 | Premature Release of Resource During Expected Lifetime | redhat-SADP |
| CWE-826 | Premature Release of Resource During Expected Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| squid-cache squid | < 7.5 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | CVE Modified | CVE |
| Mar 26, 2026 | New CVE Received | [email protected] |