Back to search
CVE-2022-38150
Published: Aug 11, 2022
Modified: Oct 20, 2025
PUBLISHED
Description
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2022-1fa6d1ed2f
vendor-advisory
FEDORA-2022-99702d9bdd
vendor-advisory
FEDORA-2022-99c5ddb2ae
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now