CVE Vulnerabilities

CVE-2022-38150

Published: Aug 11, 2022 | Modified: Oct 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.

Affected Software

NameVendorStart VersionEnd Version
Varnish_cacheVarnish_cache_project7.0.0 (including)7.0.0 (including)
Varnish_cacheVarnish_cache_project7.0.1 (including)7.0.1 (including)
Varnish_cacheVarnish_cache_project7.0.2 (including)7.0.2 (including)
Varnish_cacheVarnish_cache_project7.1.0 (including)7.1.0 (including)
VarnishUbuntutrusty*
VarnishUbuntuupstream*
VarnishUbuntuxenial*

References