VSV00019 Vinyl Cache / Varnish Cache HTTP/2 parsing deficiency

VSV00019 Vinyl Cache / Varnish Cache HTTP/2 parsing deficiency ¶ Originally published 2026-05-18, last updated 2026-05-28 A deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2 . HTTP/2 support is disabled by de

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论