Security Advisory

CVE-2022-38150

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-08-11 00:00:00
Last updated 2025-10-20 18:03:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.