diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-61642.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-61642.patch
new file mode 100644
index 0000000000..f5f2424504
--- /dev/null
+++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-61642.patch
@@ -0,0 +1,43 @@
+From d06f48de8b8cc9a378cb91ecfe8e89b6e81696d2 Mon Sep 17 00:00:00 2001
+From: Amos Jeffries <yadij@users.noreply.github.com>
+Date: Sun, 31 May 2026 08:29:04 +0000
+Subject: [PATCH] HTTP/1.1: Transfer-Encoding:identity is prohibited (#2427)
+
+HTTP specification deprecated identity encoding but still allows
+its use as an unknown encoding when the Transfer-Encoding
+header is otherwise correctly used.
+
+Squid compliance update at the time kept accepting identity
+encoding as it was being used by agents. The form supported was
+Transfer-Encoding:identity.
+
+However, the HTTP specification explicitly requires that any
+encoding MUST be wrapped within chunked encoding.
+
+As such the bare Transfer-Encoding:identity form Squid accepted
+is explicitly prohibited.
+
+The correct Transfer-Encoding:identity,chunked syntax has been
+rejected by Squid for nearly 5 years already without complaint.
+So support is being dropped entirely here.
+
+CVE: CVE-2026-61642
+Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/d06f48de8b8cc9a378cb91ecfe8e89b6e81696d2]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/HttpHeader.cc | 2 --
+ 1 file changed, 2 deletions(-)
+
+diff --git a/src/HttpHeader.cc b/src/HttpHeader.cc
+index 3e06deab6..39422123f 100644
+--- a/src/HttpHeader.cc
++++ b/src/HttpHeader.cc
+@@ -516,8 +516,6 @@ HttpHeader::parse(const char *header_start, size_t hdrLen, Http::ContentLengthIn
+ 
+         if (rawTe.caseCmp("chunked") == 0) {
+             ; // leave header present for chunked() method
+-        } else if (rawTe.caseCmp("identity") == 0) { // deprecated. no coding
+-            delById(Http::HdrType::TRANSFER_ENCODING);
+         } else {
+             // This also rejects multiple encodings until we support them properly.
+             debugs(55, warnOnError, "WARNING: unsupported Transfer-Encoding used by client: " << rawTe);
diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb
index ddaa4e48ac..0f07b38468 100644
--- a/meta-networking/recipes-daemons/squid/squid_6.14.bb
+++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb
@@ -28,6 +28,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U}
            file://CVE-2026-47729.patch \
            file://CVE-2026-50012-01.patch \
            file://CVE-2026-50012-02.patch \
+           file://CVE-2026-61642.patch \
            "
 
 SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd"
