CVE-2026-32748

Source
https://cve.org/CVERecord?id=CVE-2026-32748
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32748.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-32748
Aliases
  • GHSA-f9p7-3jqg-hhvq
Downstream
Related
Published
2026-03-26T00:11:01.424Z
Modified
2026-07-22T03:57:07.251689Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L CVSS Calculator
Summary
Squid has Denial of Service in ICP Response handling
Details

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero icp_port). This problem cannot be mitigated by denying ICP queries using icp_access rules. This bug is fixed in Squid version 7.5.

Database specific
{
    "cwe_ids": [
        "CWE-413",
        "CWE-416",
        "CWE-826"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32748.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/squid-cache/squid

Affected ranges

Type
GIT
Repo
https://github.com/squid-cache/squid
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.5"
        }
    ]
}

Affected versions

4.*
4.15-20210522-snapshot
4.15-20210523-snapshot
4.15-20210524-snapshot
4.15-20210525-snapshot
4.15-20210527-snapshot
5.*
5.0.6-20210522-snapshot
5.0.6-20210523-snapshot
5.0.6-20210524-snapshot
5.0.6-20210525-snapshot
5.0.6-20210527-snapshot
6.*
6.0.0-20210522-master-snapshot
6.0.0-20210523-master-snapshot
6.0.0-20210524-master-snapshot
6.0.0-20210525-master-snapshot
6.0.0-20210527-master-snapshot
Other
HISTORIC_RELEASES
M-staged-PR161
M-staged-PR164
M-staged-PR170
M-staged-PR176
M-staged-PR179
M-staged-PR181
M-staged-PR182
M-staged-PR186
M-staged-PR189
M-staged-PR193
M-staged-PR195
M-staged-PR196
M-staged-PR198
M-staged-PR199
M-staged-PR200
M-staged-PR202
M-staged-PR206
M-staged-PR208
M-staged-PR209
M-staged-PR210
M-staged-PR218
M-staged-PR220
M-staged-PR221
M-staged-PR225
M-staged-PR227
M-staged-PR229
M-staged-PR230
M-staged-PR235
M-staged-PR237
M-staged-PR238
M-staged-PR239
M-staged-PR241
M-staged-PR242
M-staged-PR252
M-staged-PR255
M-staged-PR258
M-staged-PR264
M-staged-PR266
M-staged-PR267
M-staged-PR268
M-staged-PR274
M-staged-PR276
M-staged-PR293
M-staged-PR294
M-staged-PR295
M-staged-PR299
M-staged-PR306
M-staged-PR314
M-staged-PR319
M-staged-PR342
M-staged-PR345
M-staged-PR348
M-staged-PR351
M-staged-PR359
M-staged-PR364
M-staged-PR365
M-staged-PR366
M-staged-PR370
M-staged-PR372
M-staged-PR373
M-staged-PR375
M-staged-PR376
SQUID_3_0_PRE1
SQUID_3_0_PRE2
SQUID_3_0_PRE3
SQUID_3_0_PRE4
SQUID_3_0_PRE5
SQUID_3_0_PRE6
SQUID_3_0_PRE7
SQUID_3_0_RC1
SQUID_3_5_27
SQUID_4_0_1
SQUID_4_0_10
SQUID_4_0_11
SQUID_4_0_12
SQUID_4_0_13
SQUID_4_0_14
SQUID_4_0_15
SQUID_4_0_16
SQUID_4_0_2
SQUID_4_0_3
SQUID_4_0_4
SQUID_4_0_5
SQUID_4_0_6
SQUID_4_0_7
SQUID_4_0_8
SQUID_4_0_9
SQUID_7_0_1
SQUID_7_0_2
SQUID_7_1
SQUID_7_2
SQUID_7_3
SQUID_7_4
take00

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32748.json"
vanir_signatures_modified
"2026-07-22T03:57:07Z"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "243352462900800681241861553990203413808",
                "300484473802938881708248863686584403596",
                "94192046996803733410238991015010850766",
                "35976842455265214243543065521283426545",
                "229907641640078050589270929510956296299",
                "172167082737990101058666970536840061876",
                "163641930995999705390020501624719436738",
                "317453058515531118909598510072130818949",
                "327947400352631882207840664111419143550",
                "293001272136621056586609424205657683755",
                "180381190634481285553315432160064717264",
                "226534930926270981059761155217759033683"
            ]
        },
        "id": "CVE-2026-32748-2ea8e6bf",
        "signature_version": "v1",
        "source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
        "target": {
            "file": "src/icp_v3.cc"
        },
        "signature_type": "Line"
    },
    {
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "77592479204099837417809566971300308802",
                "93640007456331014450897377437855106126",
                "85923554875153157910711459702461896135",
                "156180841417188105227882029211364461511",
                "63790553578942787979447307918181129897",
                "153426200801402372106083382397359041828",
                "172238237288482496949825696708765303730",
                "58585321329646447836827752796707869983"
            ]
        },
        "id": "CVE-2026-32748-4c66a6ce",
        "signature_version": "v1",
        "source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
        "target": {
            "file": "src/tests/stub_icp.cc"
        },
        "signature_type": "Line"
    },
    {
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "163238443664217658227527820259664871542",
                "161194772122636143491105187332728389983",
                "41155010299085218649387124635846205711",
                "334163032043303842847223412544935434917",
                "123347278277586112989222788660406325627"
            ]
        },
        "id": "CVE-2026-32748-7ade132f",
        "signature_version": "v1",
        "source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
        "target": {
            "file": "src/ICP.h"
        },
        "signature_type": "Line"
    },
    {
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "143219049299083245799680224445672018277",
                "133507620288559061107011467426164501248",
                "105750338835718457562939961682400813694",
                "329367724121276202040147029513888189940",
                "185207224545373747109449323206283799138",
                "181715733549568611382844065675907927980",
                "51987072570729000914091453101174906947",
                "202972085968364742990977942971448567178",
                "79690344310933407983133557548313173584",
                "43157949176886451662503532035544637426",
                "215399611952066209208022068339978501314",
                "337216827341656836071196092639906660763",
                "224246501411392178564381581149014687966",
                "162159401597642972662077874681947782670",
                "276700054631030851702431754056787204694",
                "37886212810077383301847254329446288335",
                "243352462900800681241861553990203413808",
                "300484473802938881708248863686584403596",
                "94192046996803733410238991015010850766",
                "3244951409353702419421189852534500549",
                "97836477967120141351288241780095746114",
                "179989240179146995442969106763914963558",
                "115531777033205054439919401823512600639",
                "268842568553203922878777029671612801526",
                "190371567076939501832824407893002228629",
                "237026325573650618279049640952653566882",
                "225931370375604610075599960532986683290",
                "259271198926781748697687970561561592513",
                "242092190386032709681426817625376767158",
                "67646146923418401612812543301776058541",
                "52542535036102880299306756644745597506",
                "287727481289629147172990316306414266323",
                "198927622467850337684215409583636398272",
                "220382294633158809864878730777369565649",
                "245604137560050721863709174448924315595",
                "317127261820182522361953650702915103896"
            ]
        },
        "id": "CVE-2026-32748-7e99acfd",
        "signature_version": "v1",
        "source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
        "target": {
            "file": "src/icp_v2.cc"
        },
        "signature_type": "Line"
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "100238494650514381774874016661516704907",
            "length": 487.0
        },
        "id": "CVE-2026-32748-a2cb49b9",
        "signature_version": "v1",
        "source": "https://github.com/squid-cache/squid/commit/703e07d25ca6fa11f52d20bf0bb879e22ab7481b",
        "target": {
            "function": "icpAccessAllowed",
            "file": "src/icp_v2.cc"
        },
        "signature_type": "Function"
    }
]