new file mode 100644
@@ -0,0 +1,43 @@
+From d06f48de8b8cc9a378cb91ecfe8e89b6e81696d2 Mon Sep 17 00:00:00 2001
+From: Amos Jeffries <yadij@users.noreply.github.com>
+Date: Sun, 31 May 2026 08:29:04 +0000
+Subject: [PATCH] HTTP/1.1: Transfer-Encoding:identity is prohibited (#2427)
+
+HTTP specification deprecated identity encoding but still allows
+its use as an unknown encoding when the Transfer-Encoding
+header is otherwise correctly used.
+
+Squid compliance update at the time kept accepting identity
+encoding as it was being used by agents. The form supported was
+Transfer-Encoding:identity.
+
+However, the HTTP specification explicitly requires that any
+encoding MUST be wrapped within chunked encoding.
+
+As such the bare Transfer-Encoding:identity form Squid accepted
+is explicitly prohibited.
+
+The correct Transfer-Encoding:identity,chunked syntax has been
+rejected by Squid for nearly 5 years already without complaint.
+So support is being dropped entirely here.
+
+CVE: CVE-2026-61642
+Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/d06f48de8b8cc9a378cb91ecfe8e89b6e81696d2]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/HttpHeader.cc | 2 --
+ 1 file changed, 2 deletions(-)
+
+diff --git a/src/HttpHeader.cc b/src/HttpHeader.cc
+index 3e06deab6..39422123f 100644
+--- a/src/HttpHeader.cc
++++ b/src/HttpHeader.cc
+@@ -516,8 +516,6 @@ HttpHeader::parse(const char *header_start, size_t hdrLen, Http::ContentLengthIn
+
+ if (rawTe.caseCmp("chunked") == 0) {
+ ; // leave header present for chunked() method
+- } else if (rawTe.caseCmp("identity") == 0) { // deprecated. no coding
+- delById(Http::HdrType::TRANSFER_ENCODING);
+ } else {
+ // This also rejects multiple encodings until we support them properly.
+ debugs(55, warnOnError, "WARNING: unsupported Transfer-Encoding used by client: " << rawTe);
@@ -28,6 +28,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U}
file://CVE-2026-47729.patch \
file://CVE-2026-50012-01.patch \
file://CVE-2026-50012-02.patch \
+ file://CVE-2026-61642.patch \
"
SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd"