CVE-2022-38150 is a high-severity vulnerability affecting Varnish Cache versions 7.0.0 through 7.1.0, including specific Fedora Project distributions. An unauthenticated attacker can trigger a denial-of-service by sending a specially crafted HTTP/1 backend response, causing the Varnish server to assert and restart. While the CVSS score is 7.5 (High), there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Patches are available in Varnish Cache versions 7.0.3 and 7.1.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.0CPE matchmatch criteria | cpe:2.3:a:varnish_cache_project:varnish_cache:7.0.0:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:varnish_cache_project:varnish_cache:7.0.1:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:varnish_cache_project:varnish_cache:7.0.2:*:*:*:*:*:*:* | ||
7.1.0CPE matchmatch criteria | cpe:2.3:a:varnish_cache_project:varnish_cache:7.1.0:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.