According to the website, Squid 5.x and 6.x are merely deprecated (see https://wiki.squid-cache.org/Releases/Squid-5) but in practice Squid maintainers seem to provide fixes only for 7.x, such as in this recent case: https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg
Those vulnerabilities in question are unlikely to be exploited because they require the attacker to be a trusted cache peer. However, according to https://security-tracker.debian.org/tracker/source-package/squid , Debian isn't patching those in Bookworm for Squid 5 either, so it's difficult to tell what may happen if an actually bad vulnerability is found.
It isn't difficult to tell what effect it will have on various automated security scanners: they are already upset about that.
I suspect the best way to fix that for real is to upgrade to the latest Squid from source. In my experience, compatibility issues between major version of Squid are very rare. There's a small number of removed features in release notes but none of those seem to affect us.