High severity7.5NVD Advisory· Published Apr 8, 2020· Updated Jun 17, 2026
CVE-2020-11653
CVE-2020-11653
Description
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.
Affected products
9- cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:a:varnish-cache:varnish_cache:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:varnish-cache:varnish_cache:*:*:*:*:-:*:*:*range: >=6.1.0,<6.2.3
- (no CPE)range: <6.0.6, <6.1.x, <6.2.3, <6.3.2
- cpe:2.3:a:varnish-software:varnish_cache:*:*:*:*:lts:*:*:*Range: >=6.0.0,<6.0.6
- Varnish Cache/Varnish Cachedescription
- osv-coords2 versionspkg:rpm/opensuse/varnish&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/varnish&distro=SUSE%20Package%20Hub%2015%20SP1
< 6.2.1-lp151.3.6.1+ 1 more
- (no CPE)range: < 6.2.1-lp151.3.6.1
- (no CPE)range: < 6.2.1-bp151.4.6.1
Patches
Vulnerability mechanics
References
4- lists.opensuse.org/opensuse-security-announce/2020-06/msg00026.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-06/msg00031.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/11/msg00036.htmlnvdMailing ListThird Party Advisory
- varnish-cache.org/security/VSV00005.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.