#VU66219 Reachable Assertion in Varnish Cache - CVE-2022-38150
Published: August 9, 2022 / Updated: November 28, 2022
Varnish Cache
Varnish Software
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when processing HTTP/1 responses from configured backends. A remote attacker with ability to influence server response can pass specially crafted reason phrase of the backend response status line and perform a denial of service (DoS) attack.