CVE-2026-33526Disclosure(squid-cache / squid)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch squid-cache squid systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-826CWE-825

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • squid

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-26); latest day: 2
  • 10 total mentions across 4 days

Affected systems

Products
squid

Deep dive

Activity timeline10 mentions / 4d
01345Mentions · 2026-03-25: 1Mentions · 2026-03-26: 5Mentions · 2026-03-27: 2Mentions · 2026-03-28: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 3Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 5Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 103-2503-2603-2703-28
Signal classification2 categories
Disclosure
770.0%
Patch
330.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-265
Disclosure3Patch2
2026-03-272
Disclosure2
2026-03-282
Disclosure2
Full discourse10 posts
  • Gray Hats@the_yellow_fall
    Patch

    Squid Proxy patches critical 9.2 CVSS DoS and memory leak flaws in ICP. Standard access rules won't block the attack—upgrade to version 7.5 now #SquidProxy #CyberSecurity #InfoSec #PatchAlert #Vulnerability #DoS #Networking #OpenSource #TechNews #SysAdmin https://securityonline.info/squid-proxy-icp-vulnerability-dos-cve-2026-33526/ https://t.co/a5lw3D2wzs

    Post summary

    The tweet announces a critical DoS and memory leak vulnerability (cve-2026-33526) in Squid Proxy ICP and urges users to apply the patch by upgrading to version 7.5 immediately.

    040114546
    10.9K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Squid Proxy Cache Security Update Advisories https://www.openwall.com/lists/oss-security/2026/03/25/ CVE-2026-33526,SQUID-2026:1 and CVE-2026-32748,SQUID-2026:2 Denial of Service in ICP Request handling (heap Use-After-Free bugs) CVE-2026-33515,SQUID-2026:3 Out of Bounds Read in ICP message handling (infoleak)

    Post summary

    The post lists three Squid Proxy Cache CVEs with details on denial‑of‑service and information‑leak vulnerabilities, and provides a link to security update advisories, but does not present any proof of concept, exploit code, or evidence of active exploitation.

    00060364
    4.4K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Squid プロキシに深刻なDoS脆弱性(CVE-2026-33526) https://rocket-boys.co.jp/security-measures-lab/squid-proxy-severe-dos-vulnerability-cve-2026-33526/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article announces a severe DoS vulnerability (CVE-2026-33526) in Squid Proxy, providing technical details about the issue but no proof of exploitation, PoC, or patch information.

    00011122
    364 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Use-After-Free in #Squid. CVE-2026-33526 CVSS: 9.2. This vulnerability can lead to a denial of service #DoS! #Patch #Patch #Patch More info: https://github.com/squid-cache/squid/security/advisories/GHSA-hpfx-h48q-gvwg

    Post summary

    A critical use‑after‑free vulnerability (CVE‑2026‑33526) in Squid with CVSS 9.2 is announced, capable of causing a DoS, and a patch is available via the linked GitHub advisory.

    01001198
    7.2K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🦑 CVE-2026-33526 (Squid Critical): Proxy DoS from malformed ICP queries crashes workers. Stack with CVE-2026-32748/33515 for total outage. Update Squid now! https://www.squid-cache.org/Advisory/SQUID-2026-3.txt

    Post summary

    The advisory warns that CVE‑2026‑33526 causes a DoS in Squid via malformed ICP queries and urges users to apply the patch available in the linked advisory.

    1000040
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🛡️ Squid proxies under fire: CVE-2026-33526 (Critical) DoS via malformed ICP queries crashes workers. Chain w/ CVE-2026-32748 & CVE-2026-33515 for max disruption. Update Squid branches NOW. Fresh alert Mar 25-26! https://www.squid-cache.org/Advisory/SQUID-2026-3.txt

    Post summary

    The alert announces critical DoS CVEs in Squid, provides technical details, and urges immediate patching of affected branches.

    0001049
    492 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33526 Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This probl… https://www.cve.org/CVERecord?id=CVE-2026-33526

    Post summary

    The CVE-2026-33526 vulnerability involves a heap use‑after‑free in Squid versions before 7.5, leading to a denial‑of‑service attack through ICP traffic handling; no PoC, exploit, patch, or active exploitation is referenced.

    00010139
    56.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33526: Squid vulnerable to Denial of Se... Remote attackers can reliably nuke any Squid proxy with ICP enabled through heap UAF - icp_access rules won't save you.... https://zerodaysignal.com/vulnerability/CVE-2026-33526 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a Denial of Service vulnerability (CVE‑2026‑33526) in Squid caused by a heap use‑after‑free when ICP is enabled, providing a link for further details but no PoC, exploit, patch, or active exploitation claim.

    0100074
    169 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    Squid プロキシに深刻なDoS脆弱性(CVE-2026-33526) https://rocket-boys.co.jp/security-measures-lab/squid-proxy-severe-dos-vulnerability-cve-2026-33526/

    Post summary

    An announcement has identified a serious DoS vulnerability in Squid proxy, named CVE‑2026‑33526, but no additional exploitation details are provided.

    0000039
    39 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-33526、Critical SQUID-2026:1 Denial of Service in ICP Request handling · Advisory · squid-cache/squid · GitHub https://github.com/squid-cache/squid/security/advisories/GHSA-hpfx-h48q-gvwg

    Post summary

    CVE-2026-33526 is a critical denial‑of‑service flaw in Squid’s ICP handling, with a GitHub advisory posted but no PoC, exploit code, or evidence of active exploitation provided.

    00000354
    6.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsquid-cachesquid---

Explore more