CVE-2019-20637

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-20637

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2020:4756

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
debian debianbookwormfixed6.4.0-1
debian debianbullseyefixed6.4.0-1
debian debianforkyfixed6.4.0-1
debian debiansidfixed6.4.0-1
debian debiantrixiefixed6.4.0-1

References

Verify integrity in audit chain (admin only). AS-IS.