Inconsistent interpretation of HTTP requests in Squid - CVE-2026-61642

 

Inconsistent interpretation of HTTP requests in Squid - CVE-2026-61642

Published: September 14, 2026


Vulnerability identifier: #VU149503
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61642
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass security mechanisms and poison an HTTP cache with arbitrary malicious content.

The vulnerability exists due to improper enforcement of behavioral workflow in Squid\'s HTTP/1.1 Transfer-Encoding handling when processing HTTP/1.1 requests. A remote user can perform HTTP request smuggling to bypass security mechanisms and poison an HTTP cache with arbitrary malicious content.

An HTTP cache operating before the affected Squid instance is required for cache poisoning.


Affected software

Squid

How to mitigate CVE-2026-61642

Install security update from vendor's website.

Squid - update to 7.6

External References

Related Security Bulletins