CVE-2022-45059

HIGH LAB

Varnish Cache < 7.1.2 - HTTP Request Smuggling

Title source: rule
STIX 2.1

Description

An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.

Exploits (1)

nomisec WORKING POC
by martinvks · poc
https://github.com/martinvks/CVE-2022-45059-demo

Scores

CVSS v3 7.5
EPSS 0.0152
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull amazoncorretto:17
docker pull martinvks/cve-2022-45059-frontend
docker pull martinvks/cve-2022-45059-backend
docker pull martinvks/cve-2022-45059-victim
docker pull nicolaka/netshoot
+1 more images

Details

CWE
CWE-444
Status published
Products (5)
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
varnish_cache_project/varnish_cache 7.2.0
varnish_cache_project/varnish_cache 7.0.0 - 7.1.2
Published Nov 09, 2022
Tracked Since Feb 18, 2026