Varnish Cache is a widely deployed HTTP accelerator and reverse proxy that sits in the request path of high-traffic web services, and its vulnerability profile concentrates in this single product with an elevated tendency toward serious outcomes. The recurring exposure reflects the complexity of HTTP request parsing and caching logic, surfacing weaknesses such as HTTP request smuggling, memory-buffer boundary violations, and resource-consumption flaws that can undermine cache integrity or enable denial of service. Defenders should prioritize patches for this vendor given its prominence in the web-serving tier and the tendency of its flaws to reach critical severity and confirmed exploitation; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Varnish Cache Project over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2017-8807CRITICAL vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process | Nov 16, 2017 | 9.1 | 32 | NO | NO |
CVE-2022-23959CRITICAL In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, req | Jan 26, 2022 | 9.1 | 31 | NO | NO |
CVE-2019-15892HIGH An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending craf | Sep 3, 2019 | 7.5 | 27 | NO | NO |
CVE-2022-45059HIGH An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain he | Nov 9, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-45060HIGH An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP | Nov 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-38150HIGH In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack u | Aug 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-20637HIGH An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client requ | Apr 8, 2020 | 7.5 | 25 | NO | NO |
CVE-2017-12425HIGH An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that | Aug 4, 2017 | 7.5 | 25 | NO | NO |
CVE-2021-28543HIGH Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only ins | Mar 16, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Varnish Cache Project.
Media articles that mention a CVE ID that affects a product developed by Varnish Cache Project — matched by CVE ID, not by vendor name.