#VU25016 Reachable Assertion in Varnish Cache
Published: February 7, 2020
Varnish Cache
Varnish Software
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion. when using Varnish with a TLS
termination proxy, and the proxy and Varnish use the PROXY version 2
protocol to communicate connection details. A remote attacker can send a specially crafted request to the server, cause assertion failure and restart the application, resulting in denial of service condition.