- What: Security update for Varnish with cache poisoning and authentication bypass
- Impact: Debian users should apply the update
[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6303-1] varnish security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6303-1] varnish security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Wed, 27 May 2026 21:02:30 +0000 Message-id: <[🔎] ahdb5if4CKMoS69r@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6303-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 27, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : varnish CVE ID : CVE-2025-8671 Two security issues were discovered in the the Varnish web accelerator, which could result in cache poisoning or authentication bypass. For the stable distribution (trixie), this problem has been fixed in version 7.7.0-3+deb13u1. We recommend that you upgrade your varnish packages. For the detailed security status of varnish please refer to its security tracker page at: https://security-tracker.debian.org/tracker/varnish Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoXW0IACgkQEMKTtsN8 TjZggRAArWZERXqOZEDwDU8CU+HnGzDQoV4xoaF2cg71DC7hVJz5kr3LPFxS5LJp e5ocYIq+5Ba0jKouspkUaPAqocznidNlvGC4pLNc4lTEuihL05LgzAFz37HCGHou U8th8wyznmlprRPCoDifARwUjFemwgkJPHzjlY3KH2xENV0W9aBqXCjLvca53iba 3Uh8XNqVbuiitaPlXns/qj1z21OLhQbE5gzWfuqatzwZlRMdfZxlPXMRJsG2stlD 1durjcsHOyZBqUn6YqnYkaqnHpdCw4mspecbJISIEq18btu8SnaMIB8nAOGk89Pc t5VrcFEMrIa/sgxtkThJ+Q3IlxYsCCAKuQ5kuMVCbE0dBHLmRiIxBNZdHWa49nEO bnXch5Q/oeAS8AwYc6lOuH7ylWtwWhM0qGa4RIIKqDtSHeVJH/9H2DYpb1XqAC8n qbpROceo10RfYxrpFEz7jJt0sempnGl7nk1tejsH91TaOLQj4G8ZJYh2hbAlspZW bLsaepiOkCmTVo5l+KxjvRB1TAaNwsch5yqqaR/TQPwdZR394yjsaVwtNPZjOucX dT4LJ5CYyCm+cTzsa3BQEJii2hzd4z+VnWih/fdFeRvXjIH6JaM7TPKd1TSQ7+Fc vj7IAfqoNuVIPXxf5OJa/3PxJjU/kvtyL+8hcb6ppRWQHivDKDU= =vV9z -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6302-1] starlette security update Next by Date: [SECURITY] [DSA 6304-1] unbound security update Previous by thread: [SECURITY] [DSA 6302-1] starlette security update Next by thread: [SECURITY] [DSA 6304-1] unbound security update Index(es): Date Thread