Intel

AIKIDO-2026-10090

squid-cache.squid is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 26, 2026

40

Medium Risk

This Affects:

c++squid-cache.squid
0.1 - 7.3
Fixed in 7.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package have multiple robustness issues in the ICMP handling code, including insufficient validation of packet headers and unsafe assumptions about buffer and payload sizes that could lead to undefined behavior, crashes, or denial of service. The patched version hardens ICMP echo path validation, fixes potential overflows and undefined behavior, and improves safety checks to prevent these issues.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

squid-cache.squid is vulnerable to Denial of Service (DoS) in versions 0.1 - 7.3.

How to fix this

Upgrade the squid-cache.squid library to the patch version.