Varnish is a focused, widely deployed HTTP caching and load-balancing reverse proxy whose vulnerability footprint concentrates in authentication and input-validation mechanisms at the network edge. The recurring weaknesses—improper authentication, input validation, and quantity validation—reflect the protocol-parsing and access-control demands inherent to a request-handling intermediary. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Varnish.Projects.Linpro over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2936HIGH The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication fo | Apr 5, 2010 | 7.5 | 75 | NO | YES |
CVE-2009-4488CRITICAL Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary co | Jan 13, 2010 | 9.8 | 42 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Varnish.Projects.Linpro.
Media articles that mention a CVE ID that affects a product developed by Varnish.Projects.Linpro — matched by CVE ID, not by vendor name.