#VU124611 Out-of-bounds read in Squid - CVE-2026-33515
Published: March 25, 2026
Squid
Squid-cache.org
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in ICP message handling when processing ICP traffic. A remote attacker can send a specially crafted ICP request to disclose small amounts of memory potentially containing sensitive information.
The attack is limited to Squid deployments that explicitly enable ICP support (i.e., configure a non-zero icp_port).