Varnish WAF 1.3.2 is a security and maintenance release. The headline change is an update of the vendored ModSecurity library to 3.0.17, which fixes a number of upstream security advisories, several of them WAF bypasses. The release also adds arm64 packages.
The notable changes are highlighted below. Please see the changelog for the complete list of changes.
The vendored ModSecurity library has been updated from 3.0.15 to 3.0.17. The upstream releases 3.0.16 and 3.0.17 address the following security advisories:
Content-Type header with
non-standard capitalization.SecParseXmlIntoArgs is enabled.filename* parameter or duplicated
filename parameters.t:htmlEntityDecode,
t:removeComments and t:base64DecodeExt transformations.@rx/@rxGlobal pattern, and PCRE2 match-limit errors
being treated as an ordinary no-match.\r and \n in the
multipart/form-data request body parser.Upstream also fixed CVE-2026-52761, which only affects i386 and does not apply to Varnish WAF.
Note that rules with an invalid regular expression, which earlier versions silently loaded, are now rejected at load time. Check that your rule set still loads after upgrading if you maintain custom rules.
See the ModSecurity 3.0.16 and ModSecurity 3.0.17 release notes for the full list of upstream changes.
Packages are now built and published for arm64 on the platforms where Varnish Enterprise is available on arm64.
Debian 11 (Bullseye) is end of life and packages are no longer built for it.