Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero icp_port). This problem cannot be mitigated by denying ICP queries using icp_access rules. This bug is fixed in Squid version 7.5.
{
"cwe_ids": [
"CWE-413",
"CWE-416",
"CWE-826"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32748.json",
"cna_assigner": "GitHub_M"
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.5"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32748.json"
"2026-07-22T03:57:07Z"
[
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"243352462900800681241861553990203413808",
"300484473802938881708248863686584403596",
"94192046996803733410238991015010850766",
"35976842455265214243543065521283426545",
"229907641640078050589270929510956296299",
"172167082737990101058666970536840061876",
"163641930995999705390020501624719436738",
"317453058515531118909598510072130818949",
"327947400352631882207840664111419143550",
"293001272136621056586609424205657683755",
"180381190634481285553315432160064717264",
"226534930926270981059761155217759033683"
]
},
"id": "CVE-2026-32748-2ea8e6bf",
"signature_version": "v1",
"source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
"target": {
"file": "src/icp_v3.cc"
},
"signature_type": "Line"
},
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"77592479204099837417809566971300308802",
"93640007456331014450897377437855106126",
"85923554875153157910711459702461896135",
"156180841417188105227882029211364461511",
"63790553578942787979447307918181129897",
"153426200801402372106083382397359041828",
"172238237288482496949825696708765303730",
"58585321329646447836827752796707869983"
]
},
"id": "CVE-2026-32748-4c66a6ce",
"signature_version": "v1",
"source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
"target": {
"file": "src/tests/stub_icp.cc"
},
"signature_type": "Line"
},
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"163238443664217658227527820259664871542",
"161194772122636143491105187332728389983",
"41155010299085218649387124635846205711",
"334163032043303842847223412544935434917",
"123347278277586112989222788660406325627"
]
},
"id": "CVE-2026-32748-7ade132f",
"signature_version": "v1",
"source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
"target": {
"file": "src/ICP.h"
},
"signature_type": "Line"
},
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"143219049299083245799680224445672018277",
"133507620288559061107011467426164501248",
"105750338835718457562939961682400813694",
"329367724121276202040147029513888189940",
"185207224545373747109449323206283799138",
"181715733549568611382844065675907927980",
"51987072570729000914091453101174906947",
"202972085968364742990977942971448567178",
"79690344310933407983133557548313173584",
"43157949176886451662503532035544637426",
"215399611952066209208022068339978501314",
"337216827341656836071196092639906660763",
"224246501411392178564381581149014687966",
"162159401597642972662077874681947782670",
"276700054631030851702431754056787204694",
"37886212810077383301847254329446288335",
"243352462900800681241861553990203413808",
"300484473802938881708248863686584403596",
"94192046996803733410238991015010850766",
"3244951409353702419421189852534500549",
"97836477967120141351288241780095746114",
"179989240179146995442969106763914963558",
"115531777033205054439919401823512600639",
"268842568553203922878777029671612801526",
"190371567076939501832824407893002228629",
"237026325573650618279049640952653566882",
"225931370375604610075599960532986683290",
"259271198926781748697687970561561592513",
"242092190386032709681426817625376767158",
"67646146923418401612812543301776058541",
"52542535036102880299306756644745597506",
"287727481289629147172990316306414266323",
"198927622467850337684215409583636398272",
"220382294633158809864878730777369565649",
"245604137560050721863709174448924315595",
"317127261820182522361953650702915103896"
]
},
"id": "CVE-2026-32748-7e99acfd",
"signature_version": "v1",
"source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
"target": {
"file": "src/icp_v2.cc"
},
"signature_type": "Line"
},
{
"deprecated": false,
"digest": {
"function_hash": "100238494650514381774874016661516704907",
"length": 487.0
},
"id": "CVE-2026-32748-a2cb49b9",
"signature_version": "v1",
"source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
"target": {
"function": "icpAccessAllowed",
"file": "src/icp_v2.cc"
},
"signature_type": "Function"
}
]