CVE-2026-33526: Squid Uaf Rfc1738 Escape

Double-escaping a string with rfc1738_escape or reusing its return value as its own input leads to a Use-After-Free. The rfc1738_escape function manages a static internal buffer that can be dynamically reallocated. Passing the returned pointer back into rfc1738_escape can cause the function to read from the buffer after it has been freed during reallocation.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C++
greprules fetch cve-2026-33526-squid-uaf-rfc1738-escape --engine opengrep

Description

Double-escaping a string with rfc1738_escape or reusing its return value as its own input leads to a Use-After-Free. The rfc1738_escape function manages a static internal buffer that can be dynamically reallocated. Passing the returned pointer back into rfc1738_escape can cause the function to read from the buffer after it has been freed during reallocation.