CVE-2021-36740
MEDIUMVarnish-cache Varnish Cache < 6.0.8 - HTTP Request Smuggling
Title source: ruleDescription
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.
References (7)
Scores
CVSS v3
6.5
EPSS
0.0071
EPSS Percentile
72.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-444
Status
published
Products (9)
debian/debian_linux
10.0
debian/debian_linux
11.0
fedoraproject/fedora
33
fedoraproject/fedora
34
varnish-cache/varnish_cache
6.0.8 r1 (2 CPE variants)
varnish-cache/varnish_cache
6.0.0 - 6.0.8
varnish-software/varnish_cache
6.0.0 - 6.0.5
varnish-software/varnish_cache
6.0.0 - 6.0.7
varnish_cache_project/varnish_cache
5.0.0 - 5.2.1
Published
Jul 14, 2021
Tracked Since
Feb 18, 2026