Inconsistent interpretation of HTTP requests in Squid - CVE-2026-61642
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to bypass security mechanisms and poison an HTTP cache with arbitrary malicious content.
The vulnerability exists due to improper enforcement of behavioral workflow in Squid\'s HTTP/1.1 Transfer-Encoding handling when processing HTTP/1.1 requests. A remote user can perform HTTP request smuggling to bypass security mechanisms and poison an HTTP cache with arbitrary malicious content.
An HTTP cache operating before the affected Squid instance is required for cache poisoning.