https://seclists.org/oss-sec/2025/q2/131: VSV00016: Varnish Cache 6.0, 7.6, 7.7 - quest Smuggling Attack
Published May 13, 2025
·Updated
Affected Software
1 affected component
Varnish Software Varnish Cache>=6.0.14<=7.7.1
Frequently Asked Questions
1
What is the severity of VSV00016?
VSV00016 is considered a critical vulnerability due to its potential for exploitation through request smuggling attacks.
2
How do I fix VSV00016?
To mitigate VSV00016, it is recommended to upgrade Varnish Cache to the latest version provided by the vendor.
3
Which versions of Varnish Cache are affected by VSV00016?
VSV00016 affects Varnish Cache versions 6.0, 7.6, and 7.7.
4
What type of attack is associated with VSV00016?
VSV00016 is associated with a request smuggling attack that can lead to unauthorized data access.
5
Is there a CVE identifier for VSV00016?
As of the announcement, no CVE identifier has been assigned for VSV00016, but it may be provided in the future.