From 8a7d42f9d44befb8fcbbb619505587c8de6a1e91 Mon Sep 17 00:00:00 2001 From: Joshua Rogers Date: Tue, 10 Feb 2026 19:58:49 +0000 Subject: [PATCH] Do not escape malformed URI twice when sending ICP errors (#2374) In this context, escaping escaped URI always produces incorrect URI because `%` character in the escaped URI gets escaped again. Feeding the result of the first rfc1738_escape() call to the second call is also dangerously wrong because the result of the first call gets invalidated during the second call. No other cases of such "chained" rfc1738_escape() calls were found. Broken since 2002 commit e6ccf245. Upstream: https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165 CVE: CVE-2026-33526 Signed-off-by: Thomas Perale --- src/icp_v2.cc | 1 - 1 file changed, 1 deletion(-) diff --git a/src/icp_v2.cc b/src/icp_v2.cc index 2a4ced3bfab..25f7b71d25e 100644 --- a/src/icp_v2.cc +++ b/src/icp_v2.cc @@ -490,7 +490,6 @@ HttpRequest * icpGetRequest(const char * const url, const int reqnum, const int fd, const Ip::Address &from) { if (strpbrk(url, w_space)) { - url = rfc1738_escape(url); icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr); return nullptr; }