https://seclists.org/oss-sec/2025/q2/127: VSV00016: Varnish Cache 6.0, 7.6, 7.7 - quest Smuggling Attack
Published May 13, 2025
·Updated
Affected Software
1 affected component
Varnish Software Varnish Cache
Frequently Asked Questions
1
What is the severity of VSV00016?
The severity of VSV00016 is categorized as critical due to the potential for client-side desynchronization attacks.
2
How do I fix VSV00016?
To fix VSV00016, you should upgrade to Varnish Cache version 7.7.1, 7.6.3, or 6.0.14.
3
What systems are affected by VSV00016?
VSV00016 affects Varnish Cache versions 6.0, 7.6, and 7.7.
4
What type of vulnerability is VSV00016?
VSV00016 is a client-side desync vulnerability that allows for potential request smuggling.
5
Is there a CVE assigned for VSV00016?
No, a CVE has not been assigned yet for VSV00016.