CVE-2026-33515 Details
Description
Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive information when responding with errors to invalid ICP requests. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem cannot be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.
A vulnerability allowing out of bounds read has been identified in Squid versions prior to 7.5. This issue arises from improper input validation when the proxy handles Internet Cache Protocol (ICP) traffic. The vulnerability allows remote attackers to access small amounts of memory that may contain sensitive information, by sending invalid ICP requests that elicit error responses. This issue affects Squid deployments with ICP support enabled, as indicated by a non-zero 'icp_port' configuration. Notably, the vulnerability cannot be mitigated by using 'icp_access' rules to deny ICP queries.
Upgrade to Squid version 7.5, where this vulnerability has been fixed. For users of earlier versions, a patch is available in the Squid patch archives. If using a prepackaged version of Squid, consult the package vendor for update availability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/03/25/4 | CVE | Mailing ListThird Party Advisory |
| https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165 | [email protected] | Patch |
| https://github.com/squid-cache/squid/pull/2220 | [email protected] | Issue Tracking |
| https://github.com/squid-cache/squid/pull/2220#discussion_r2727683637 | [email protected] | Issue Tracking |
| https://github.com/squid-cache/squid/security/advisories/GHSA-84p4-hcx7-jj7c | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-1289 | Improper Validation of Unsafe Equivalence in Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| squid-cache squid | < 7.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |
| Mar 26, 2026 | CVE Modified | CVE |