Varnish Cache
Vendor:
First CVE: Nov 1, 2013 · Active for 12 years
16
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 39% of tracked products
6.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Varnish Cache over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 2013
12 years ago
Most Recent CVE
Mar 21, 2025
490 days ago
CVE Severity & Scoring
Varnish Cache16 CVEs
19%
63%
13%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (87.5%)
Unknown2 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (81.3%)
High1 (6.3%)
Unknown2 (12.5%)
User Interaction
None14 (87.5%)
Unknown2 (12.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (87.5%)
Unknown2 (12.5%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2017-8807CRITICAL vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process | Nov 16, 2017 | 9.1 | 32 | NO | NO |
CVE-2022-23959CRITICAL In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, req | Jan 26, 2022 | 9.1 | 31 | NO | NO |
CVE-2019-15892HIGH An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending craf | Sep 3, 2019 | 7.5 | 27 | NO | NO |
CVE-2022-45059HIGH An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain he | Nov 9, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-45060HIGH An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP | Nov 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-38150HIGH In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack u | Aug 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-20637HIGH An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client requ | Apr 8, 2020 | 7.5 | 25 | NO | NO |
CVE-2017-12425HIGH An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that | Aug 4, 2017 | 7.5 | 25 | NO | NO |
CVE-2013-4090HIGH Varnish HTTP cache before 3.0.4: ACL bug | Feb 12, 2020 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
1 CVE
6.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Varnish Cache
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.2.0 | 2 | 7.5 | 1.1% | 0 | 0 |
| 7.1.0 | 1 | 7.5 | 1.2% | 0 | 0 |
| 7.0.2 | 1 | 7.5 | 1.2% | 0 | 0 |
| 7.0.1 | 1 | 7.5 | 1.2% | 0 | 0 |
| 7.0.0 | 1 | 7.5 | 1.2% | 0 | 0 |
| 6.0.8 | 1 | 6.5 | 1.6% | 0 | 0 |
| 5.1.2 | 1 | 7.5 | 2.4% | 0 | 0 |
| 5.1.1 | 1 | 7.5 | 2.4% | 0 | 0 |
| 5.1.0 | 1 | 7.5 | 2.4% | 0 | 0 |
| 5.0.0 | 1 | 7.5 | 2.4% | 0 | 0 |
| 4.0.4 | 1 | 7.5 | 2.4% | 0 | 0 |
| 4.0.3 | 1 | 7.5 | 2.4% | 0 | 0 |
| 4.0.2 | 1 | 7.5 | 2.4% | 0 | 0 |
| 4.0.1 | 1 | 7.5 | 2.4% | 0 | 0 |
| 3.0.6 | 1 | 7.5 | 3.5% | 0 | 0 |
| 3.0.5 | 1 | 7.5 | 3.5% | 0 | 0 |
| 3.0.4 | 1 | 7.5 | 3.5% | 0 | 0 |
| 3.0.3 | 3 | 4.9 | 2.3% | 0 | 0 |
| 3.0.2 | 2 | 6.3 | 3.3% | 0 | 0 |
| 3.0.1 | 2 | 6.3 | 3.3% | 0 | 0 |