Squid has Denial of Service in ICP Response handling
Published Mar 26, 2026
8.7
HIGHCVSS 4.0
EPSS 9.98%
Description
Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.
Affected products
-
- Version < 7.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Squid-Cache | Squid | n/a |
|
- < 7.5
No data.
Red Hat Enterprise Linux 10
squid-7:6.10-6.el10_1.3
Fixed · RHSA-2026:8119
Red Hat Enterprise Linux 10.0 Extended Update Support
squid-7:6.10-5.el10_0.2
Fixed · RHSA-2026:11901
Red Hat Enterprise Linux 7 Extended Lifecycle Support
squid-7:3.5.20-17.el7_9.16
Fixed · RHSA-2026:8880
Red Hat Enterprise Linux 8
squid:4-8100020260408092701.489197e6
Fixed · RHSA-2026:8317
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
squid:4-8040020260514123440.522a0ee4
Fixed · RHSA-2026:20564
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
squid:4-8040020260514123440.522a0ee4
Fixed · RHSA-2026:20564
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
squid:4-8060020260518090356.ad008a3a
Fixed · RHSA-2026:20565
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
squid:4-8060020260518090356.ad008a3a
Fixed · RHSA-2026:20565
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
squid:4-8060020260518090356.ad008a3a
Fixed · RHSA-2026:20565
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
squid:4-8080020260514105733.63b34585
Fixed · RHSA-2026:20580
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
squid:4-8080020260514105733.63b34585
Fixed · RHSA-2026:20580
Red Hat Enterprise Linux 9
squid-7:5.5-22.el9_7.4
Fixed · RHSA-2026:6301
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
squid-7:5.2-1.el9_0.10
Fixed · RHSA-2026:10256
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
squid-7:5.5-5.el9_2.11
Fixed · RHSA-2026:10257
Red Hat Enterprise Linux 9.4 Extended Update Support
squid-7:5.5-13.el9_4.5
Fixed · RHSA-2026:10255
Red Hat Enterprise Linux 9.6 Extended Update Support
squid-7:5.5-19.el9_6.3
Fixed · RHSA-2026:9220
Red Hat Enterprise Linux 6
squid
Out of support scope
Red Hat Enterprise Linux 6
squid34
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | squid-7:6.10-6.el10_1.3 | Fixed | RHSA-2026:8119 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | squid-7:6.10-5.el10_0.2 | Fixed | RHSA-2026:11901 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | squid-7:3.5.20-17.el7_9.16 | Fixed | RHSA-2026:8880 |
| Red Hat Enterprise Linux 8 | squid:4-8100020260408092701.489197e6 | Fixed | RHSA-2026:8317 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | squid:4-8040020260514123440.522a0ee4 | Fixed | RHSA-2026:20564 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | squid:4-8040020260514123440.522a0ee4 | Fixed | RHSA-2026:20564 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | squid:4-8060020260518090356.ad008a3a | Fixed | RHSA-2026:20565 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | squid:4-8060020260518090356.ad008a3a | Fixed | RHSA-2026:20565 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | squid:4-8060020260518090356.ad008a3a | Fixed | RHSA-2026:20565 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | squid:4-8080020260514105733.63b34585 | Fixed | RHSA-2026:20580 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | squid:4-8080020260514105733.63b34585 | Fixed | RHSA-2026:20580 |
| Red Hat Enterprise Linux 9 | squid-7:5.5-22.el9_7.4 | Fixed | RHSA-2026:6301 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | squid-7:5.2-1.el9_0.10 | Fixed | RHSA-2026:10256 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | squid-7:5.5-5.el9_2.11 | Fixed | RHSA-2026:10257 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | squid-7:5.5-13.el9_4.5 | Fixed | RHSA-2026:10255 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | squid-7:5.5-19.el9_6.3 | Fixed | RHSA-2026:9220 |
| Red Hat Enterprise Linux 6 | squid | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | squid34 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Important flaw in Squid can lead to a Denial of Service when processing specially crafted Internet Cache Protocol (ICP) traffic. This vulnerability affects Red Hat products running Squid if ICP support is explicitly enabled by configuring a non-zero `icp_port`. Deployments where ICP is not enabled by default are not affected.
Red Hat mitigation
To mitigate this issue, ensure that ICP support is not explicitly enabled in the Squid configuration. This can be achieved by commenting out or setting `icp_port` to `0` in the `squid.conf` file. After modifying the configuration, the Squid service must be reloaded or restarted for the changes to take effect. Example: ``` # icp_port 3130 ``` or ``` icp_port 0 ``` Warning: Reloading or restarting the Squid service may temporarily interrupt proxy services.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Mar 26, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.98% (0.09977) | 95.47th | v5 (v2026.06.15) |
| Jun 30, 2026 | 8.93% (0.08931) | 94.59th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.73% (0.02734) | 84.14th | v5 (v2026.06.15) |
| Apr 21, 2026 | 0.35% (0.00349) | 57.40th | v4 (v2025.03.14) |
| Mar 26, 2026 | 1.80% (0.01797) | 82.68th | v4 (v2025.03.14) |
References (20)
- http://www.openwall.com/lists/oss-security/2026/03/25/3 Mailing ListMitigationPatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:10255
- https://access.redhat.com/errata/RHSA-2026:10256
- https://access.redhat.com/errata/RHSA-2026:10257
- https://access.redhat.com/errata/RHSA-2026:11901
- https://access.redhat.com/errata/RHSA-2026:20564
- https://access.redhat.com/errata/RHSA-2026:20565
- https://access.redhat.com/errata/RHSA-2026:20580
- https://access.redhat.com/errata/RHSA-2026:6301
- https://access.redhat.com/errata/RHSA-2026:8119
- https://access.redhat.com/errata/RHSA-2026:8317
- https://access.redhat.com/errata/RHSA-2026:8880
- https://access.redhat.com/errata/RHSA-2026:9220
- https://access.redhat.com/security/cve/CVE-2026-32748 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451577 Issue Tracking
- https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b x_refsource_MISCPatch
- https://github.com/squid-cache/squid/security/advisories/GHSA-f9p7-3jqg-hhvq x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-32748
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32748.json
- https://www.cve.org/CVERecord?id=CVE-2026-32748
Change history (0)
No recorded changes yet.