Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-docs | Apr 11, 2024 | Mar 24, 2024 |
| Alpine Linux | — | Upgrade varnish | Jun 6, 2024 | Mar 24, 2024 |
| Debian | — | Upgrade varnish | May 15, 2025 | Mar 24, 2024 |
| Oracle_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-docs | Apr 9, 2024 | Mar 24, 2024 |
| Redhat_linux | — | Upgrade varnish-develUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-modules-debugsourceUpgrade varnishUpgrade varnish-modules-debuginfo | Apr 9, 2024 | Mar 24, 2024 |
| Rocky_linux | — | Upgrade varnish-modulesUpgrade varnish-develUpgrade varnish-docsUpgrade varnish-modules-debuginfoUpgrade varnishUpgrade varnish-modules-debugsource | May 8, 2024 | Mar 24, 2024 |
| Suse | — | Upgrade varnish-develUpgrade libvarnishapi3Upgrade varnish | Dec 5, 2025 | Dec 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub