Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1151 articles · 105240 vulns · 38/41 feeds (7d)
← Back to list
7.5
CVE-2026-32748EXPLOITED
squid-cache · squid

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when ha

Description

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

Affected Products

VendorProductVersions
squid-cachesquid< 7.5, 3.x -> 3.5.28, 4.x -> 4.17, 5.x -> 5.9, 6.x -> 6.14, 7.x -> 7.4

References

  • https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b
  • https://github.com/squid-cache/squid/security/advisories/GHSA-f9p7-3jqg-hhvq
  • http://www.openwall.com/lists/oss-security/2026/03/25/3

Related News (4 articles)

Tier A
Microsoft MSRC2h ago
CVE-2026-32748 Squid has Denial of Service in ICP Response handling
→ No new info (linked only)
Tier B
BSI Advisories1d ago
[UPDATE] [hoch] Squid: Mehrere Schwachstellen ermöglichen Denial of Service
→ No new info (linked only)
Tier C
oss-security2d ago
[ADVISORY] SQUID-2026:2 Denial of Service in ICP Request handling (CVE-2026-32748)
→ No new info (linked only)
Tier B
CERT-FR2d ago
Multiples vulnérabilités dans Squid (25 mars 2026)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-413, CWE-416, CWE-826
Published3/26/2026
Last enriched3h agov3
Trending Score65
Source articles4
Independent4
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v3
Last enriched 3h ago
v3Tier C3h ago

Updated exploit availability to true, marked as actively exploited, and confirmed patch version 7.5.

exploitAvailableactivelyExploited
via oss-security
v2Tier C10h ago

Updated affected versions to include Squid 3.x to 7.x, marked exploit as available and actively exploited, and confirmed patch available in version 7.5.

affectedVersionspatchAvailable
via oss-security
v112h ago

Initial creation