CVE-2026-33526

EUVD-2026-16068
Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 94.74%
Affected Products (NVD)
VendorProductVersion
squid-cachesquid
𝑥
< 7.5
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
7:6.10-6.el10_1.3 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
7:6.10-5.el10_0.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
7:3.5.20-17.el7_9.16 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8100020260408092701.489197e6 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
8040020260514123440.522a0ee4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
8040020260514123440.522a0ee4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
8060020260518090356.ad008a3a ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service
8060020260518090356.ad008a3a ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions
8060020260518090356.ad008a3a ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
8080020260514105733.63b34585 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
8080020260514105733.63b34585 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
7:5.5-22.el9_7.4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions
7:5.2-1.el9_0.10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
7:5.5-5.el9_2.11 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
7:5.5-13.el9_4.5 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
7:5.5-19.el9_6.3 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
squid
bookworm
vulnerable
bookworm (security)
5.7-2+deb12u6
fixed
bullseye
vulnerable
bullseye (security)
4.13-10+deb11u7
fixed
forky
7.6-2
fixed
sid
7.6-2
fixed
trixie
6.13-2+deb13u2
fixed
trixie (security)
6.13-2+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squid
focal
needs-triage
jammy
Fixed 5.9-0ubuntu0.22.04.5
released
noble
Fixed 6.14-0ubuntu0.24.04.2
released
questing
Fixed 6.14-0ubuntu0.25.10.2
released
resolute
not-affected
squid3
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
squid
RHEL 9
7:5.5-22.el9_7.4
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
squid
Amazon Linux 2
7:3.5.20-17.amzn2.7.26
fixed
Amazon Linux 2023
7:6.13-1.amzn2023.0.4
fixed
squid-debuginfo
Amazon Linux 2
7:3.5.20-17.amzn2.7.26
fixed
Amazon Linux 2023
7:6.13-1.amzn2023.0.4
fixed
squid-debugsource
Amazon Linux 2023
7:6.13-1.amzn2023.0.4
fixed
squid-migration-script
Amazon Linux 2
7:3.5.20-17.amzn2.7.26
fixed
squid-sysvinit
Amazon Linux 2
7:3.5.20-17.amzn2.7.26
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
squid
Azure Linux 3.0
0:6.13-4.azl3
fixed