logo

Squid Caching Proxy Alert: Critical ICP Protocol Flaws Threaten Web Infrastructure

ID: 4a1b8e2c-30e3-5315-9de5-c2c3660875a8

STIX ID: report--4a1b8e2c-30e3-5315-9de5-c2c3660875a8

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

Squid's Internet Cache Protocol (ICP) implementation contains multiple serious vulnerabilities — two heap Use-After-Free bugs enabling reliable remote Denial of Service and a memory-disclosure flaw (CVE-2026-33515, CVSS 6.9) that can leak internal proxy memory. The issues affect Squid versions 3.0 through 7.4 when ICP is enabled (non-zero icp_port); they cannot be mitigated by icp_access rules. The vendor released fixes in Squid 7.5 and backported commits for the stable 7 branch; immediate mitigation is to disable ICP or set icp_port to 0 until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.