Back

HIGH

varnish: HTTP/2 request smuggling attack via a large Content-Length header for a POST request

Published Jul 14, 2021

Description

Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.

Affected products

Remediation

Red Hat mitigation

This issue can be mitigated by: 1) Disabling HTTP/2 request support by executing: ~~~ sudo varnishadm param.set feature -http2 ~~~ 2) Disabling backend connection reuse on varnish side, the following rule can be inserted into Varnish configuration: ~~~ sub vcl_backend_fetch { set bereq.http.Connection = "close"; } ~~~

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 14, 2021
Updated Aug 4, 2024
Reserved Jul 14, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 13, 2021