Search CVE reports


Toggle filters

1 – 10 of 25 results


CVE-2026-40396

Medium priority
Needs evaluation

Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40395

Medium priority
Needs evaluation

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40394

Medium priority
Needs evaluation

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34475

Medium priority
Needs evaluation

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8671

Medium priority

Some fixes available 2 of 23

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to...

5 affected packages

h2o, haproxy, lighttpd, varnish, dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2o Needs evaluation Needs evaluation Needs evaluation Needs evaluation
haproxy Not affected Not affected Not affected Not affected
lighttpd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dnsdist Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-47905

Medium priority
Needs evaluation

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-30346

Medium priority
Needs evaluation

Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-30156

Medium priority
Ignored

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Ignored Ignored Not affected Not affected
Show less packages

CVE-2022-45060

Medium priority

Some fixes available 3 of 6

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-45059

Medium priority
Ignored

An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish...

1 affected package

varnish

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
varnish Not affected Not affected Not affected Not affected
Show less packages