Varnish Software
varnish-software
13 CVEs • 5 products
Products (5)
Click to collapseToggle
Products (5)
Click to collapse
CVEs (13)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Varnish Software 1Varnish Enterprise Jun 17, 2026 Apr 12, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally...Show more |
2Varnish Software Vinyl Cache2Varnish Enterprise Vinyl CacheJun 17, 2026 Apr 12, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a spe...Show more |
2Varnish Software Vinyl Cache2Varnish Enterprise Vinyl CacheJun 17, 2026 Mar 27, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. |
1Varnish Software 1Varnish Enterprise Jun 17, 2026 Mar 21, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects. |
2Varnish Software Varnish Cache Project2Varnish Cache Varnish EnterpriseJun 17, 2026 Mar 21, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. |
1Varnish Software 2Varnish Enterprise Vmod DigestJun 17, 2026 Aug 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the...Show more |
4Debian FedoraprojectVarnish Software+1 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in th...Show more |
4Debian FedoraprojectVarnish Software+1 more6Debian Linux FedoraVarnich Cache+3 moreJun 17, 2026 Jan 26, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 conn...Show more |
5Debian FedoraprojectVarnish Cache+2 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x...Show more |
4Debian OpensuseVarnish Cache+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Apr 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion f...Show more |
3Opensuse Varnish CacheVarnish Software4Backports Sle LeapVarnish Cache+1 moreJun 17, 2026 Apr 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same...Show more |
3Debian Varnish SoftwareVarnish Cache Project3Debian Linux Varnish CacheVarnish CacheJun 17, 2026 Sep 3, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cau...Show more |
3Varnish Cache Varnish SoftwareVarnish Cache Project3Varnish Varnish CacheVarnish CacheMay 13, 2026 Aug 4, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the cli...Show more |