High severity7.5NVD Advisory· Published Nov 9, 2022· Updated Jun 17, 2026
CVE-2022-45059
CVE-2022-45059
Description
An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:*range: >=7.0.0,<7.1.2
- cpe:2.3:a:varnish_cache_project:varnish_cache:7.2.0:*:*:*:*:*:*:*
- (no CPE)range: <7.1.2, <7.2.1
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- Varnish Cache/Varnish Cachedescription
- osv-coords12 versionspkg:bitnami/varnishpkg:deb/ubuntu/[email protected]?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:rpm/opensuse/varnish&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/varnish&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/vinyl-cache&distro=openSUSE%20Tumbleweedpkg:rpm/suse/varnish&distro=SUSE%20Package%20Hub%2015%20SP4
>= 7.0.0, < 7.1.2+ 11 more
- (no CPE)range: >= 7.0.0, < 7.1.2
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 7.2.1-bp154.2.9.1
- (no CPE)range: < 7.2.1-1.1
- (no CPE)range: < 9.0.0-1.1
- (no CPE)range: < 7.2.1-bp154.2.9.1
Patches
Vulnerability mechanics
References
4- varnish-cache.org/security/VSV00010.htmlnvdMitigationVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6ZMOZVBLZXHEV5VRW4I4SOWLQEK5OF5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4KVVCIQVINQQ2D7ORNARSYALMJUMP3I/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGF6LFTHXCSYMYUX5HLMVXQH3WHCSFLU/nvd
News mentions
0No linked articles in our index yet.