varnish-software records
13 published records for vendor varnish-software.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 69.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')3
- CWE-617 Reachable Assertion2
- CWE-180 Incorrect Behavior Order: Validate Before Canonicalize1
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
- CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-34475No exploit | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / varnish-software · varnish enterprise · CWE-180 | Critical9.8 | — | 0.4% | Mar 27, 2026 |
37Monitor | CVE-2022-23959No exploit | In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x beforvarnish-software · varnich cache · CWE-444 | Critical9.1 | — | 2.0% | Jan 25, 2022 |
32Monitor | CVE-2019-15892No exploit | An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1.varnish-software · varnish cache · CWE-617 | High7.5 | — | 5.8% | Sep 3, 2019 |
31Monitor | CVE-2017-12425No exploit | An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.varnish-cache · varnish · CWE-190 | High7.5 | — | 2.4% | Aug 4, 2017 |
31Monitor | CVE-2020-11653No exploit | An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.varnish-cache · varnish cache · CWE-617 | High7.5 | — | 2.2% | Apr 8, 2020 |
31Monitor | CVE-2019-20637No exploit | An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.varnish-cache · varnish cache · CWE-212 | High7.5 | — | 1.8% | Apr 8, 2020 |
30Monitor | CVE-2022-45060No exploit | An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1.varnish-software · varnish cache · CWE-20 | High7.5 | — | 1.0% | Nov 9, 2022 |
30Monitor | CVE-2026-40394No exploit | Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certvarnish-software · varnish enterprise · CWE-670 | High7.5 | — | 0.4% | Apr 12, 2026 |
30Monitor | CVE-2026-40395No exploit | Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL.varnish-software · varnish enterprise · CWE-770 | High7.5 | — | 0.4% | Apr 12, 2026 |
30Monitor | CVE-2025-30347No exploit | Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on varnish-software · varnish enterprise · CWE-125 | High7.5 | — | 0.3% | Mar 21, 2025 |
26Monitor | CVE-2021-36740No exploit | Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST requevarnish-cache · varnish cache · CWE-444 | Medium6.5 | — | 1.6% | Jul 14, 2021 |
26Monitor | CVE-2023-41104No exploit | libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding,varnish-software · varnish enterprise · CWE-119 | Medium6.5 | — | 0.6% | Aug 23, 2023 |
19Monitor | CVE-2025-30346No exploit | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.varnish-software · varnish enterprise · CWE-444 | Medium4.8 | — | 0.3% | Mar 21, 2025 |
- CVE-2026-3447539Monitor
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of /
CriticalCVSS 9.8No exploitEPSS 0%varnish-software · varnish enterpriseMar 27, 2026
- CVE-2022-2395937Monitor
In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x befor
CriticalCVSS 9.1No exploitEPSS 2%varnish-software · varnich cacheJan 25, 2022
- CVE-2019-1589232Monitor
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1.
HighCVSS 7.5No exploitEPSS 6%varnish-software · varnish cacheSep 3, 2019
- CVE-2017-1242531Monitor
An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.
HighCVSS 7.5No exploitEPSS 2%varnish-cache · varnishAug 4, 2017
- CVE-2020-1165331Monitor
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.
HighCVSS 7.5No exploitEPSS 2%varnish-cache · varnish cacheApr 8, 2020
- CVE-2019-2063731Monitor
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.
HighCVSS 7.5No exploitEPSS 2%varnish-cache · varnish cacheApr 8, 2020
- CVE-2022-4506030Monitor
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1.
HighCVSS 7.5No exploitEPSS 1%varnish-software · varnish cacheNov 9, 2022
- CVE-2026-4039430Monitor
Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for cert
HighCVSS 7.5No exploitEPSS 0%varnish-software · varnish enterpriseApr 12, 2026
- CVE-2026-4039530Monitor
Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL.
HighCVSS 7.5No exploitEPSS 0%varnish-software · varnish enterpriseApr 12, 2026
- CVE-2025-3034730Monitor
Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on
HighCVSS 7.5No exploitEPSS 0%varnish-software · varnish enterpriseMar 21, 2025
- CVE-2021-3674026Monitor
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST reque
MediumCVSS 6.5No exploitEPSS 2%varnish-cache · varnish cacheJul 14, 2021
- CVE-2023-4110426Monitor
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding,
MediumCVSS 6.5No exploitEPSS 1%varnish-software · varnish enterpriseAug 23, 2023
- CVE-2025-3034619Monitor
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
MediumCVSS 4.8No exploitEPSS 0%varnish-software · varnish enterpriseMar 21, 2025