In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
https://www.debian.org/security/2022/dsa-5088
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UMMDMQWNAE3BTSZUHXQHVAMZC5TLHLYT/
https://lists.debian.org/debian-lts-announce/2022/02/msg00014.html
https://github.com/VLPraneeth/praneeth-cve-bin-tool
https://github.com/swesmith-repos/intel__cve-bin-tool.5219b964
https://github.com/CVEDB/cve-bin-tool
https://github.com/intel/cve-bin-tool
https://varnish-cache.org/security/VSV00008.html
https://docs.varnish-software.com/security/VSV00008/
Source: Mitre, NVD
Published: 2022-01-26
Updated: 2026-06-17
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: Critical
EPSS: 0.00209