An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-develUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish | Dec 6, 2022 | Nov 9, 2022 |
| Alpine Linux | — | Upgrade varnish | Aug 22, 2024 | Nov 9, 2022 |
| Centos_linux | — | Upgrade varnish-develUpgrade varnish-modulesUpgrade varnish-modules-debuginfoUpgrade varnish-docsUpgrade varnishUpgrade varnish-modules-debugsource | Nov 29, 2022 | Nov 9, 2022 |
| Debian | — | Upgrade varnish | Nov 29, 2022 | Nov 9, 2022 |
| Gentoo Linux | — | Upgrade www-servers/vinyl-cache. | Aug 26, 2026 | Aug 26, 2026 |
| Oracle_linux | — | Upgrade varnish-develUpgrade varnish-docsUpgrade varnishUpgrade varnish-modules | Nov 29, 2022 | Nov 8, 2022 |
| Redhat_linux | — | Upgrade varnish-develUpgrade varnish-modules-debugsourceUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-modules-debuginfoUpgrade varnish | Nov 29, 2022 | Nov 9, 2022 |
| Rocky_linux | — | Upgrade varnish-modules-debuginfoUpgrade varnishUpgrade varnish-develUpgrade varnish-docsUpgrade varnish-modules-debugsourceUpgrade varnish-modules | Mar 12, 2024 | Nov 9, 2022 |
| Suse | — | Upgrade libvarnishapi3Upgrade varnishUpgrade varnish-devel | Nov 14, 2022 | Nov 9, 2022 |
| Ubuntu | — | Upgrade libvarnishapi1 (Ubuntu Pro)Upgrade varnish (Ubuntu Pro)Upgrade libvarnishapi2 (Ubuntu Pro) | Mar 27, 2025 | Nov 9, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub