Varnish-software

Varnish Enterprise

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 12.04.2026 19:21:09
  • Zuletzt bearbeitet 17.04.2026 14:37:34

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request...

  • EPSS 0.06%
  • Veröffentlicht 12.04.2026 19:17:34
  • Zuletzt bearbeitet 17.04.2026 14:35:23

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and...

  • EPSS 0.07%
  • Veröffentlicht 27.03.2026 19:40:28
  • Zuletzt bearbeitet 22.04.2026 19:40:02

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

  • EPSS 0.86%
  • Veröffentlicht 13.08.2025 12:03:37
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By op...

  • EPSS 0.29%
  • Veröffentlicht 13.05.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

  • EPSS 0.4%
  • Veröffentlicht 21.03.2025 00:00:00
  • Zuletzt bearbeitet 02.04.2025 22:15:20

Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

  • EPSS 0.35%
  • Veröffentlicht 21.03.2025 00:00:00
  • Zuletzt bearbeitet 24.03.2025 14:19:23

Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.

  • EPSS 0.18%
  • Veröffentlicht 23.08.2023 07:15:08
  • Zuletzt bearbeitet 21.11.2024 08:20:35

libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depe...