Varnish Cache and Varnish Enterprise Request Smuggling Vulnerability in HTTP/2

Vulnerability

A request smuggling vulnerability has been identified in Varnish Cache and Varnish Enterprise servers with HTTP/2 enabled. This issue allows attackers to bypass VCL authorization by sending POST requests with large Content-Length headers. The vulnerability affects Varnish Cache versions 5.x and 6.x prior to 6.5.2, as well as Varnish Enterprise 6.0.x prior to 6.0.8r3. The request smuggling can be exploited by sending crafted HTTP/2 requests that are not properly processed, potentially leading to unauthorized access or cache poisoning.

Impact

Exploitation of this vulnerability can cause request smuggling, allowing attackers to bypass authorization and manipulate cached content. In some cases, the responses to smuggled requests can be retrieved by the attacker.

Reproduction

To reproduce this vulnerability, enable HTTP/2 on a Varnish server and send a POST request with a large Content-Length header. The server will process the request in a way that bypasses normal VCL authorization, allowing any authorization checks to be skipped. After the request is smuggled, it may be possible to retrieve the response, depending on the circumstances.

Remediation

Users can upgrade to Varnish Cache versions 6.5.2, 6.6.1, or 6.0.8, or to Varnish Enterprise 6.0.8r3. Instructions for upgrading Varnish on RedHat, Ubuntu, and Debian are available in the Varnish Cache VSV00007 announcement.

Added: Jun 22, 2026, 11:20 AM
Updated: Jun 22, 2026, 11:20 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
5.0
exploitability
8.7
remediation
8.3
relevance
0.0
threat
4.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.