CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Varnish Software 1Varnish Enterprise Jun 17, 2026 Apr 12, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally...Show more |
2Varnish Software Vinyl Cache2Varnish Enterprise Vinyl CacheJun 17, 2026 Apr 12, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a spe...Show more |
2Varnish Software Vinyl Cache2Varnish Enterprise Vinyl CacheJun 17, 2026 Mar 27, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. |
1Varnish Software 1Varnish Enterprise Jun 17, 2026 Mar 21, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects. |
2Varnish Software Varnish Cache Project2Varnish Cache Varnish EnterpriseJun 17, 2026 Mar 21, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. |
1Varnish Software 2Varnish Enterprise Vmod DigestJun 17, 2026 Aug 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the...Show more |