{"id":"DHI-2yy2-ox2p-bl4g-we3r","summary":"An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x…","details":"An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.\n\n---\n- varnish 7.1.1-1.1 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1023751)\nhttps://varnish-cache.org/security/VSV00011.html\nhttps://github.com/varnishcache/varnish-cache/commit/515a93df894430767073ccd8265497b6b25b54b5","modified":"2026-08-07T05:44:06.301019452Z","published":"2026-07-24T20:25:39Z","upstream":["CVE-2022-45060","DEBIAN-CVE-2022-45060","DSA-5334-1"],"references":[{"type":"ADVISORY","url":"https://scout.docker.com/v/DHI-2yy2-ox2p-bl4g-we3r"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-45060"}],"affected":[{"package":{"name":"curl","ecosystem":"Docker Hardened Images:Alpine:3.23","purl":"pkg:apk/dhi/curl?os_distro=alpine&os_name=dhi&os_version=3.23"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.5.0-r0"}]}],"versions":["8.4.0-r0"],"database_specific":{"source":"https://github.com/docker-hardened-images/advisories-test/blob/main/osv/DHI-2yy2-ox2p-bl4g-we3r.json"}}],"schema_version":"1.8.0"}