CVE-2026-61642

Public on 2026-09-18
Modified on 2026-09-18
Description
Due to a CWE-841 Improper Enforcement of Behavioral Workflow
bug Squid is vulnerable to a Request Smuggling attack against
HTTP/1.1 Transfer-Encoding.

This problem allows a trusted client to perform an HTTP Request
Smuggling attack when HTTP/1.1 is used. Bypassing security
mechanisms that may be in place between attacker and Squid.

When there is an HTTP cache operating prior to the affected
Squid, this Request Smuggling attack also allows the attacker
to poison that web cache and store arbitrary malicious content
at any URL for delivery to other clients future requests.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.7
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core squid Pending Fix
Amazon Linux 2 - Squid4 Extra squid No Fix Planned
Amazon Linux 2023 squid Pending Fix
Amazon Linux 2027 Preview squid Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N