CVE-2019-15892: Debian Linux
High severity, CVSS 7.5. EPSS: 5.9% chance of exploitation in the next 30 days.
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.
Affected products
- Debian Debian Linux: version 10.0 only
- Varnish-Software Varnish Cache: from 6.0.0, before 6.0.4 (fixed in 6.0.4)
- Varnish Cache Project Varnish Cache: from 6.1.0, up to and including 6.1.1; from 6.2.0, before 6.2.1 (fixed in 6.2.1)
Published 2019-09-03. Last modified 2026-06-17.