CVE-2013-4090
Linux Debian vulnerability analysis and mitigation

Overview

Varnish HTTP cache before version 3.0.4 contained an Access Control List (ACL) bug identified as CVE-2013-4090. The vulnerability was discovered and disclosed in June 2013, affecting all versions of Varnish HTTP cache prior to the 3.0.4 release (Varnish Announce). The vulnerability received a CVSS v3.1 base score of 7.5 (HIGH) (NVD).

Technical details

The vulnerability stems from two bugs in the code that compiles VCL ACLs into C code. The issue specifically affects non-class CIDR ACL entries (i.e., /xx except /8, /16, /24) when more specific ACL entries are present. When the CIDR split byte matches a more specific entry, the CIDR mask is rounded up to a byte boundary, causing the ACL to match less than it should. In cases where the CIDR split byte does not match the more specific entry, the CIDR entry is ignored where the split byte matches the tested IP number (Varnish Announce).

Impact

The primary impact of this vulnerability is that ACLs match fewer IP addresses than they should. This becomes particularly concerning when ACLs are used to deny access, as some IP addresses that should have been denied might slip through the security controls. The bug affects both IPv4 and IPv6 addresses equally (Varnish Announce).

Mitigation and workarounds

The vulnerability was fixed in Varnish version 3.0.4. For older versions, a patch was provided that modifies the lib/libvcl/vcc_acl.c file to correct the ACL compilation logic. Users were advised to either upgrade to version 3.0.4 or apply the provided patch (Varnish Announce).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-33230HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33229HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33228HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33231MEDIUM6.7
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-15281N/AN/A
  • WolfiWolfi
  • glibc-langpack-anp
NoYesJan 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management