CVE-2022-23959: Critical severity varnish cache vulnerability
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23959?
CVE-2022-23959 is a vulnerability in Varnish Cache that allows request smuggling for HTTP/1 connections.
What is the severity of CVE-2022-23959?
CVE-2022-23959 has a severity level of critical (9.1).
How can request smuggling occur in Varnish Cache?
Request smuggling can occur in Varnish Cache due to a vulnerability in versions before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4.
Which software versions are affected by CVE-2022-23959?
CVE-2022-23959 affects Varnish Cache versions before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4.
How can I fix CVE-2022-23959?
To fix CVE-2022-23959, it is recommended to upgrade to Varnish Cache 6.6.2 or 7.x 7.0.2, Varnish Cache 6.0 LTS 6.0.10, or Varnish Enterprise (Cache Plus) 4.1.x 4.1.11r6 or 6.0.x 6.0.9r4.