VYPR
Medium severity6.5NVD Advisory· Published Jul 14, 2021· Updated Jun 17, 2026

CVE-2021-36740

CVE-2021-36740

Description

Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

16
  • cpe:2.3:a:varnish-cache:varnish_cache:*:*:*:*:plus:*:*:*+ 3 more
    • cpe:2.3:a:varnish-cache:varnish_cache:*:*:*:*:plus:*:*:*range: >=6.0.0,<6.0.8
    • cpe:2.3:a:varnish-cache:varnish_cache:6.0.8:r1:*:*:plus:*:*:*
    • cpe:2.3:a:varnish-cache:varnish_cache:6.0.8:r2:*:*:plus:*:*:*
    • cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:*range: >=5.0.0,<=5.2.1
  • cpe:2.3:a:varnish-software:varnish_cache:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:varnish-software:varnish_cache:*:*:*:*:*:*:*:*range: >=6.0.0,<=6.0.5
    • cpe:2.3:a:varnish-software:varnish_cache:*:*:*:*:lts:*:*:*range: >=6.0.0,<=6.0.7
    • (no CPE)range: <6.5.2, <6.6.1, <6.0.8 LTS, <6.0.8r3
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • Varnish/Varnish Cachedescription
  • Range: <6.0.8r3
  • osv-coords3 versions
    >= 5.0.0, < 5.2.2+ 2 more
    • (no CPE)range: >= 5.0.0, < 5.2.2
    • (no CPE)range: < 7.1.0-bp153.2.3.1
    • (no CPE)range: < 7.1.0-bp153.2.3.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.