#VU124610 Use After Free in Squid - CVE-2026-33526
Published: March 25, 2026
Squid
Squid-cache.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap use-after-free in ICP request handling when processing ICP traffic. A remote attacker can send a specially crafted ICP request to cause a denial of service.
The attack is limited to Squid deployments that have ICP support enabled via a non-zero icp_port configuration.