Search

Varnish Enterprise 6.0.12r1 Release

Published October 23, 2023.

About the release

This release adds mitigations for the recently uncovered CVE-2023-44487.

These mitigations address a denial of service attack where an attacker can rapidly create a large volume of HTTP/2 streams and immediately reset them, causing Varnish to consume unnecessary resources for processing requests where the response will not be delivered.

See the changelog for a detailed description of the added mitigations.

References