Varnish Cache Project
varnish_cache_project
14 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (14)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Varnish Software Varnish Cache Project2Varnish Cache Varnish EnterpriseJun 17, 2026 Mar 21, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
4Debian FedoraprojectVarnish Software+1 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in th...Show more |
2Fedoraproject Varnish Cache Project2Fedora Varnish CacheJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing th...Show more |
2Fedoraproject Varnish Cache Project2Fedora Varnish CacheJun 17, 2026 Aug 11, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backe...Show more |
4Debian FedoraprojectVarnish Software+1 more6Debian Linux FedoraVarnich Cache+3 moreJun 17, 2026 Jan 26, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 conn...Show more |
5Debian FedoraprojectVarnish Cache+2 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x...Show more |
1Varnish Cache Project 1Varnish Cache Nov 21, 2024 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Varnish HTTP cache before 3.0.4: ACL bug |
3Debian Varnish SoftwareVarnish Cache Project3Debian Linux Varnish CacheVarnish CacheJun 17, 2026 Sep 3, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cau...Show more |
3Debian Varnish CacheVarnish Cache Project3Debian Linux VarnishVarnish CacheMay 13, 2026 Nov 16, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer...Show more |
3Varnish Cache Varnish SoftwareVarnish Cache Project3Varnish Varnish CacheVarnish CacheMay 13, 2026 Aug 4, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the cli...Show more |
2Debian Varnish Cache Project2Debian Linux Varnish CacheMay 6, 2026 Apr 25, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage re...Show more |
varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, which allows local users to obtain sensitive information by reading the files. NOTE: some of these de...Show more |
2Varnish Cache Varnish Cache Project2Varnish Varnish CacheApr 29, 2026 Nov 1, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI. |