The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.795
EPSS Ranking 99.0%