CVE-2022-23959 Details
Description
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
A request smuggling vulnerability has been identified in Varnish Cache versions prior to 6.6.2 and 7.x prior to 7.0.2, as well as in Varnish Cache 6.0 LTS versions prior to 6.0.10. Additionally, Varnish Enterprise (Cache Plus) versions 4.1.x prior to 4.1.11r6 and 6.0.x prior to 6.0.9r4 are affected. This vulnerability allows smuggled requests to be processed as normal requests by the Varnish server, potentially leading to information disclosure and cache poisoning.
Users can upgrade to Varnish Cache versions 6.6.2, 7.0.2, or 6.0.10, or to Varnish Enterprise versions 4.1.11r6 or 6.0.9r4. After upgrading, Varnish should be restarted. For Debian users, the upgrade can be done using the package manager. Fedora users can also upgrade through the package manager.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| varnish-software varnich cache | >= 1.0.0, < 6.6.2 >= 4.1.1, < 4.1.11r6 4.1 |
CPE
Remediation
| |
| varnish-software varnish cache | >= 6.0.0, < 6.0.10 |
CPE
Remediation
| |
| varnish-software varnish cache plus | >= 6.0.0, < 6.0.9r4 |
CPE
Remediation
| |
| varnish cache project varnish cache | >= 7.0.0, < 7.0.2 |
CPE
Remediation
| |
| fedoraproject fedora | 35 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 11.0 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Aug 2, 2022 | CPE Deprecation Remap | [email protected] |
| Aug 2, 2022 | CPE Deprecation Remap | [email protected] |
| Aug 2, 2022 | CPE Deprecation Remap | [email protected] |
| Mar 17, 2022 | Modified Analysis | [email protected] |
| Mar 4, 2022 | CVE Modified | [email protected] |
| Feb 16, 2022 | CVE Modified | [email protected] |
| Feb 14, 2022 | CVE Modified | [email protected] |
| Feb 7, 2022 | Initial Analysis | [email protected] |