Varnish Software maintains a narrowly focused caching and HTTP-acceleration platform that, despite a small product portfolio, occupies a prominent role in web-infrastructure deployments as a reverse proxy and content-delivery layer. The vendor's vulnerability profile centers on its core Varnish Cache product and related offerings, with disclosed issues spanning input validation, authentication, and protocol-handling concerns characteristic of edge-facing intermediary software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Varnish Software over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34475CRITICAL Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cac | Mar 27, 2026 | 9.8 | 35 | NO | NO |
CVE-2022-23959CRITICAL In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, req | Jan 26, 2022 | 9.1 | 31 | NO | NO |
CVE-2026-40395HIGH Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates | Apr 12, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-40394HIGH Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setu | Apr 12, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-40396HIGH Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough | Apr 12, 2026 | 7.5 | 28 | NO | NO |
CVE-2019-15892HIGH An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending craf | Sep 3, 2019 | 7.5 | 27 | NO | NO |
CVE-2022-45060HIGH An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP | Nov 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-20637HIGH An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client requ | Apr 8, 2020 | 7.5 | 25 | NO | NO |
CVE-2017-12425HIGH An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that | Aug 4, 2017 | 7.5 | 25 | NO | NO |
CVE-2021-36740MEDIUM Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0. | Jul 14, 2021 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Varnish Software.
Media articles that mention a CVE ID that affects a product developed by Varnish Software — matched by CVE ID, not by vendor name.