CVE-2026-32748Disclosure(squid-cache / squid)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch squid-cache squid systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-413CWE-416CWE-826

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • squid

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-26); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
squid

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-26: 3Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-26: 2Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 103-2603-2703-28
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-263
Disclosure2Patch1
2026-03-271
Patch1
2026-03-281
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Squid Proxy Cache Security Update Advisories https://www.openwall.com/lists/oss-security/2026/03/25/ CVE-2026-33526,SQUID-2026:1 and CVE-2026-32748,SQUID-2026:2 Denial of Service in ICP Request handling (heap Use-After-Free bugs) CVE-2026-33515,SQUID-2026:3 Out of Bounds Read in ICP message handling (infoleak)

    Post summary

    The advisory announces three new Squid CVEs with denial‑of‑service and information‑leak vulnerabilities; no PoC, exploit, or patch details are provided.

    00060364
    4.4K followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    🦑 CVE-2026-33526 (Squid Critical): Proxy DoS from malformed ICP queries crashes workers. Stack with CVE-2026-32748/33515 for total outage. Update Squid now! https://www.squid-cache.org/Advisory/SQUID-2026-3.txt

    Post summary

    The tweet announces the discovery of CVE-2026-33526, a critical Squid proxy DoS vulnerability, provides technical details about the attack vector, and urges users to apply the official update.

    1000040
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🛡️ Squid proxies under fire: CVE-2026-33526 (Critical) DoS via malformed ICP queries crashes workers. Chain w/ CVE-2026-32748 & CVE-2026-33515 for max disruption. Update Squid branches NOW. Fresh alert Mar 25-26! https://www.squid-cache.org/Advisory/SQUID-2026-3.txt

    Post summary

    A fresh advisory alerts to critical DoS vulnerabilities (CVE‑2026‑33526 and related CVEs) in Squid, recommending immediate patching of affected branches.

    0001049
    492 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32748 Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulne… https://www.cve.org/CVERecord?id=CVE-2026-32748

    Post summary

    The post announces CVE‑2026‑32748, noting a heap use‑after‑free vulnerability in Squid versions prior to 7.5 caused by premature resource release.

    00010133
    56.8K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2026-32748、High SQUID-2026:2 Denial of Service in ICP Request handling · Advisory · squid-cache/squid · GitHub https://github.com/squid-cache/squid/security/advisories/GHSA-f9p7-3jqg-hhvq

    Post summary

    Squid CVE-2026-32748 is a high‑severity denial‑of‑service flaw described in a GitHub advisory, implying that a patch has been published.

    00000325
    6.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsquid-cachesquid---

Explore more