CVE-2021-36740

MEDIUM

Varnish-cache Varnish Cache < 6.0.8 - HTTP Request Smuggling

Title source: rule
STIX 2.1

Description

Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.

Scores

CVSS v3 6.5
EPSS 0.0071
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-444
Status published
Products (9)
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 33
fedoraproject/fedora 34
varnish-cache/varnish_cache 6.0.8 r1 (2 CPE variants)
varnish-cache/varnish_cache 6.0.0 - 6.0.8
varnish-software/varnish_cache 6.0.0 - 6.0.5
varnish-software/varnish_cache 6.0.0 - 6.0.7
varnish_cache_project/varnish_cache 5.0.0 - 5.2.1
Published Jul 14, 2021
Tracked Since Feb 18, 2026