CVE-2026-33515: Squid has issues in ICP message handling
Squid has issues in ICP message handling
Other sources
Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive information when responding with errors to invalid ICP requests. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero icpport). This problem cannot be mitigated by denying ICP queries using icpaccess rules. Version 7.5 contains a patch.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33515?
CVE-2026-33515 is classified as a medium severity vulnerability due to its potential for information leakage.
How do I fix CVE-2026-33515?
To mitigate CVE-2026-33515, upgrade Squid to version 7.5 or later where the vulnerability has been addressed.
What kind of attacks can exploit CVE-2026-33515?
CVE-2026-33515 can be exploited by remote attackers to decode sensitive information from out of bounds reads during ICP message handling.
Which versions of Squid are affected by CVE-2026-33515?
CVE-2026-33515 affects Squid versions prior to 7.5.
What is the nature of the vulnerability in CVE-2026-33515?
CVE-2026-33515 involves improper input validation leading to out of bounds read issues in the handling of ICP traffic.