{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3arust-langrust/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:haskell:process_library:*:*:*:*:*:*:*:*","cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*","cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","cpe:2.3:a:rust-lang:rust:*:*:*:*:*:*:*:*","cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-3566"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Varnish HTTP Cache (CVE-2024-3566)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","dos","webserver"],"_cs_type":"advisory","_cs_vendors":["Varnish Software"],"content_html":"\u003cp\u003eThe BSI has reported a security vulnerability in Varnish HTTP Cache that can be exploited by a remote, unauthenticated attacker to cause a Denial of Service (DoS) condition. The vulnerability, tracked as CVE-2024-3566, impacts the availability of the Varnish service. When successfully exploited, an attacker can crash the Varnish process or exhaust system resources, rendering the caching layer unavailable for downstream clients. This is particularly concerning for environments relying on Varnish to handle high-traffic web requests, as the outage could lead to significant performance degradation or total failure of the backend web applications protected by the cache. Defenders should review current Varnish deployments and ensure they are patched against this identified vulnerability to prevent potential service disruptions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a Denial of Service, which can disrupt business operations by rendering web services inaccessible or severely limited. The impact is primarily on service availability for any sector utilizing Varnish HTTP Cache for high-performance content delivery.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all Varnish HTTP Cache installations within the environment using asset management tools.\u003c/li\u003e\n\u003cli\u003eReview the Varnish Software security advisories for the specific patch version addressing CVE-2024-3566.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided patches or updates to all vulnerable Varnish instances.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual spikes in request traffic or service restarts that may indicate attempted exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T13:09:22Z","date_published":"2026-09-17T13:09:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-varnish-cache-dos/","summary":"A vulnerability in Varnish HTTP Cache allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially causing service instability or resource exhaustion.","title":"Varnish HTTP Cache Denial of Service Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-varnish-cache-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:rust-Lang:rust:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}