PT-2026-28165 · Squid+4 · Squid+5

·

CVE-2026-33526

·

Published

2026-01-01

·

Updated

2026-07-06

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Squid versions prior to 7.5
Description A heap Use-After-Free issue exists when handling Internet Cache Protocol (ICP) traffic. This allows a remote attacker to perform a reliable and repeatable Denial of Service attack, making the service unavailable. The issue is limited to deployments where ICP support is explicitly enabled by configuring a non-zero icp port. This cannot be mitigated by using icp access rules. Use-After-Free is a condition where a program continues to use a pointer after it has been freed, which can lead to crashes or memory corruption.
Recommendations Update to version 7.5. As a temporary workaround, disable ICP support by setting the icp port to zero.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:6301
ALSA-2026:8119
ALSA-2026:8317
BDU:2026-07242
CVE-2026-33526
GHSA-HPFX-H48Q-GVWG
MGASA-2026-0094
RHSA-2026:10255
RHSA-2026:10256
RHSA-2026:10257
RHSA-2026:11901
RHSA-2026:6301
RHSA-2026:8119
RHSA-2026:8317
RHSA-2026:8880
RHSA-2026:9220
USN-8157-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Squid
Squid Cache
Ubuntu