Back

HIGH

varnish: http smuggling issues

Published Apr 25, 2016

Description

Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 25, 2016
Updated Aug 6, 2024
Reserved Apr 18, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 12, 2015