Unknown · Varnish Cache · CVE-2022-38150
**Name of the Vulnerable Software and Affected Versions**
Varnish Cache versions 7.0.0 through 7.0.2
Varnish Cache version 7.1.0
**Description**
The issue allows an attacker to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. This is achieved by using a crafted reason phrase of the backend response status line.
**Recommendations**
For Varnish Cache versions 7.0.0 through 7.0.2, update to version 7.0.3 to resolve the issue.
For Varnish Cache version 7.1.0, update to version 7.1.1 to resolve the issue.