CVE-2015-8852: Debian Linux
High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
Affected products
- Debian Debian Linux: version 7.0 only
- Varnish Cache Project Varnish Cache: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.0.5 only; …
Published 2016-04-25. Last modified 2026-06-17.