Varnish-Software / Varnish Cache
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-93894 | In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a r… | LOW | 2.3 | Sep 18, 2026 |
| CVE-2026-40396 | varnish: Varnish Cache: Denial of Service via workspace overflow during HTTP/1 pipelining | HIGH | 7.5 | Apr 12, 2026 |
| CVE-2026-40394 | Varnish Cache: Varnish Enterprise: Varnish Cache and Varnish Enterprise: Denial of Service via workspace overflow | HIGH | 7.5 | Apr 12, 2026 |
| CVE-2026-34475 | Varnish Cache: Varnish Cache and Varnish Enterprise: Cache poisoning and authentication bypass via unchecked URL handling | CRITICAL | 9.8 | Mar 27, 2026 |
| CVE-2025-8671 | CVE-2025-8671 | HIGH | 7.5 | Aug 13, 2025 |
| CVE-2025-47905 | varnish: request smuggling attacks | HIGH | 8.1 | May 13, 2025 |
| CVE-2025-30346 | varnish: Client-Side Desynchronization in Varnish Cache | MEDIUM | 5.4 | Mar 21, 2025 |
| CVE-2022-45060 | varnish: Request Forgery Vulnerability | HIGH | 7.5 | Nov 9, 2022 |
| CVE-2022-23959 | varnish: HTTP/1 request smuggling vulnerability | CRITICAL | 9.1 | Jan 26, 2022 |
| CVE-2021-36740 | varnish: HTTP/2 request smuggling attack via a large Content-Length header for a POST request | HIGH | 8.1 | Jul 14, 2021 |
| CVE-2019-20637 | varnish: not clearing pointer between two client requests leads to information disclosure | HIGH | 7.5 | Apr 8, 2020 |
| CVE-2020-11653 | varnish: remote clients may cause Varnish to assert and restart which could result in DoS | HIGH | 7.5 | Apr 8, 2020 |
| CVE-2019-15892 | varnish: denial of service handling certain crafted HTTP/1 requests | HIGH | 7.5 | Sep 3, 2019 |
| CVE-2017-12425 | varnish: Missing check for integer overflow when handling chunk sizes in HTTP requests | HIGH | 7.5 | Aug 4, 2017 |
Showing 1 to 7 of 7 CVEs