Varnish Cache PROXY v2 Protocol Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Varnish Cache versions prior to 6.0.6 LTS, 6.1.x, 6.2.x prior to 6.2.3, and 6.3.x prior to 6.3.2. The issue arises when Varnish communicates with a TLS termination proxy using PROXY version 2, leading to an assertion failure that causes the Varnish daemon to restart. This restart empties the cache, resulting in performance degradation and increased load on backend servers.

Impact

Exploitation of this vulnerability causes Varnish to assert and restart, emptying the cache and leading to performance losses due to increased cache misses. This may also cause higher load on backend servers.

Remediation

Users can switch to proxy protocol version 1 if their TLS termination proxy supports it. For those using Hitch as the TLS proxy, non-matching SNI names can be disallowed, and the session workspace can be increased to mitigate the issue. Varnish Cache versions 6.2.3, 6.3.2, and 6.0.6 LTS by Varnish Software include the fix.

Added: Jun 22, 2026, 12:18 PM
Updated: Jun 22, 2026, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
7.9
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.