Varnish Modules Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Varnish Modules versions prior to 0.17.1. When used with Varnish Cache version 6.5 or later, the 'header.append()' and 'header.copy()' functions can be exploited by remote attackers to trigger an assertion failure or NULL pointer dereference. This issue is not present in organizations that only use Varnish Cache, as the vulnerable 'header' vmod is only available with the separate varnish-modules package. The exploitation of this vulnerability can cause the Varnish Cache daemon to restart, leading to increased cache misses, reduced performance, and higher load on backend servers.

Impact

Exploitation of this vulnerability causes the Varnish Cache daemon to restart, which decreases availability and performance due to more cache misses, and can increase load on backend servers.

Remediation

Users can update to Varnish Modules version 0.17.1 or later. To mitigate the issue in VCL, a workspace check can be implemented before calls to 'header.append()' and 'header.copy()'.

Added: Jun 22, 2026, 11:19 AM
Updated: Jun 22, 2026, 11:19 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
7.2
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.