CVE-2019-15892

HIGH

Varnish Cache <6.0.4 LTS, 6.1.x, 6.2.x - DoS

Title source: llm
STIX 2.1

Description

An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.

References (8)

Core 8
Core References
Vendor Advisory x_refsource_misc
https://varnish-cache.org/security/VSV00003.html
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Sep/5
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4514

Scores

CVSS v3 7.5
EPSS 0.0590
EPSS Percentile 92.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-617
Status published
Products (3)
debian/debian_linux 10.0
varnish-software/varnish_cache 6.0.0 - 6.0.4
varnish_cache_project/varnish_cache 6.1.0 - 6.1.1
Published Sep 03, 2019
Tracked Since Feb 18, 2026