Skip to content
Noroxi

varnish-software records

13 published records for vendor varnish-software.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
69.2%
Median publish → KEV
No record has entered KEV

All records

13 records
  • Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of /

    CriticalCVSS 9.8No exploitEPSS 0%

    varnish-software · varnish enterpriseMar 27, 2026

  • In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x befor

    CriticalCVSS 9.1No exploitEPSS 2%

    varnish-software · varnich cacheJan 25, 2022

  • An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1.

    HighCVSS 7.5No exploitEPSS 6%

    varnish-software · varnish cacheSep 3, 2019

  • An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2.

    HighCVSS 7.5No exploitEPSS 2%

    varnish-cache · varnishAug 4, 2017

  • An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2.

    HighCVSS 7.5No exploitEPSS 2%

    varnish-cache · varnish cacheApr 8, 2020

  • An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1.

    HighCVSS 7.5No exploitEPSS 2%

    varnish-cache · varnish cacheApr 8, 2020

  • An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1.

    HighCVSS 7.5No exploitEPSS 1%

    varnish-software · varnish cacheNov 9, 2022

  • Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for cert

    HighCVSS 7.5No exploitEPSS 0%

    varnish-software · varnish enterpriseApr 12, 2026

  • Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL.

    HighCVSS 7.5No exploitEPSS 0%

    varnish-software · varnish enterpriseApr 12, 2026

  • Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on

    HighCVSS 7.5No exploitEPSS 0%

    varnish-software · varnish enterpriseMar 21, 2025

  • Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST reque

    MediumCVSS 6.5No exploitEPSS 2%

    varnish-cache · varnish cacheJul 14, 2021

  • libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding,

    MediumCVSS 6.5No exploitEPSS 1%

    varnish-software · varnish enterpriseAug 23, 2023

  • Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

    MediumCVSS 4.8No exploitEPSS 0%

    varnish-software · varnish enterpriseMar 21, 2025