https://seclists.org/oss-sec/2026/q1/400: [ADVISORY] SQUID-2026:1 Denial of Service in ICP quest handling (CVE-2026-33526)
Published Mar 28, 2026
·Updated
Affected Software
1 affected component
Squid Squid
Frequently Asked Questions
1
What is the severity of CVE-2026-33526?
CVE-2026-33526 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2026-33526?
To fix CVE-2026-33526, update to the latest version of Squid that contains the patch for this vulnerability.
3
What causes the CVE-2026-33526 vulnerability?
CVE-2026-33526 is caused by a heap Use-After-Free bug in Squid's handling of ICP traffic.
4
What systems are affected by CVE-2026-33526?
CVE-2026-33526 affects all versions of Squid prior to the patched release.
5
What impact does CVE-2026-33526 have on Squid?
CVE-2026-33526 can lead to Denial of Service, causing unavailability of the Squid server.