VSV00019 Vinyl Cache / Varnish Cache HTTP/2 parsing deficiency
VSV00019 Vinyl Cache / Varnish Cache HTTP/2 parsing deficiency ¶ Originally published 2026-05-18, last updated 2026-05-28 A deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2 . HTTP/2 support is disabled by de
评论
?
参与讨论