Varnish Cache is a narrowly scoped, open-source HTTP accelerator and caching layer widely embedded in content-delivery and web-application architectures, despite a minimal product footprint. Its vulnerability disclosures center on the core Varnish caching engine and related modules, reflecting the parsing and state-management complexity of a request-handling intermediary positioned between clients and origin servers. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Varnish Cache over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2017-8807CRITICAL vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process | Nov 16, 2017 | 9.1 | 32 | NO | NO |
CVE-2022-23959CRITICAL In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, req | Jan 26, 2022 | 9.1 | 31 | NO | NO |
CVE-2019-15892HIGH An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending craf | Sep 3, 2019 | 7.5 | 27 | NO | NO |
CVE-2022-45059HIGH An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain he | Nov 9, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-45060HIGH An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP | Nov 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-38150HIGH In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack u | Aug 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-20637HIGH An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client requ | Apr 8, 2020 | 7.5 | 25 | NO | NO |
CVE-2017-12425HIGH An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that | Aug 4, 2017 | 7.5 | 25 | NO | NO |
CVE-2021-28543HIGH Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only ins | Mar 16, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Varnish Cache.
Media articles that mention a CVE ID that affects a product developed by Varnish Cache — matched by CVE ID, not by vendor name.