<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Varnish</title>
  <link>https://cvedaily.com/pages/tags/varnish.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/varnish.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Varnish</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:30 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-50052 – In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-50052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-50052</guid>
    <pubDate>Wed, 03 Jun 2026 06:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-50052</strong></p>
  <p>In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40396 – Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40396</guid>
    <pubDate>Sun, 12 Apr 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40396</strong></p>
  <p>Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linger) and resume traffic before the session is closed (timeout_idle) sending more than one request at once to trigger a pipelining operation between requests. This…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40395 – Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40395</guid>
    <pubDate>Sun, 12 Apr 2026 20:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40395</strong></p>
  <p>Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writable from VCL). This is useful in the active VCL, after amending req, to prepare a refined req0 before s…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40394 – Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40394</guid>
    <pubDate>Sun, 12 Apr 2026 20:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40394</strong></p>
  <p>Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurposed as stream zero. During the upgrade, a buffer allocation is made to reserve space to send frame…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34475 – Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34475</guid>
    <pubDate>Fri, 27 Mar 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34475</strong></p>
  <p>Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13864 – The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13864</guid>
    <pubDate>Thu, 19 Feb 2026 07:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13864</strong></p>
  <p>The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentication being disabled by default when the API is enabled. This makes it possible for unauthenticated a…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24525 – Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24525</guid>
    <pubDate>Fri, 23 Jan 2026 15:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24525</strong></p>
  <p>Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CLP Varnish Cache: from n/a through <= 1.0.2.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62126 – Insertion of Sensitive Information Into Sent Data vulnerability in Razvan Stanga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62126</guid>
    <pubDate>Wed, 31 Dec 2025 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62126</strong></p>
  <p>Insertion of Sensitive Information Into Sent Data vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Retrieve Embedded Sensitive Data.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62867 – Missing Authorization vulnerability in ergonet Ergonet Cache ergonet-varnish-cac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62867</guid>
    <pubDate>Tue, 09 Dec 2025 16:18:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62867</strong></p>
  <p>Missing Authorization vulnerability in ergonet Ergonet Cache ergonet-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ergonet Cache: from n/a through <= 1.0.13.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58807 – Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache pu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58807</guid>
    <pubDate>Fri, 05 Sep 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58807</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache purge-varnish allows Stored XSS.This issue affects Purge Varnish Cache: from n/a through <= 2.6.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48360 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48360</guid>
    <pubDate>Thu, 28 Aug 2025 13:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48360</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Stored XSS.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47905 – Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47905</guid>
    <pubDate>Tue, 13 May 2025 22:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47905</strong></p>
  <p>Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31616 – Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31616</guid>
    <pubDate>Mon, 31 Mar 2025 13:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31616</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress varnish-wp allows Cross Site Request Forgery.This issue affects Varnish WordPress: from n/a through <= 1.7.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30347 – Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30347</guid>
    <pubDate>Fri, 21 Mar 2025 07:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30347</strong></p>
  <p>Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30346 – Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30346</guid>
    <pubDate>Fri, 21 Mar 2025 07:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30346</strong></p>
  <p>Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13269 – Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13269</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13269</strong></p>
  <p>Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30156 – Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30156</guid>
    <pubDate>Sun, 24 Mar 2024 01:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30156</strong></p>
  <p>Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Broke Window Attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-41104 – libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41104</guid>
    <pubDate>Wed, 23 Aug 2023 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-41104</strong></p>
  <p>libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-1929 – The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1929</guid>
    <pubDate>Thu, 06 Apr 2023 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-1929</strong></p>
  <p>The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the wpfc_purgecache_varnish_callback function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers with subscriber-level access to purge the varnish cache.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-1920 – The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1920</guid>
    <pubDate>Thu, 06 Apr 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-1920</strong></p>
  <p>The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_purgecache_varnish_callback function. This makes it possible for unauthenticated attackers to purge the varnish cache via a forged request granted they can trick a site administrator into performing an actio…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45060 – An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45060</guid>
    <pubDate>Wed, 09 Nov 2022 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45060</strong></p>
  <p>An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a ser…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45059 – An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45059</guid>
    <pubDate>Wed, 09 Nov 2022 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45059</strong></p>
  <p>An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38150 – In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Var...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38150</guid>
    <pubDate>Thu, 11 Aug 2022 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38150</strong></p>
  <p>In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24745 – Shopware is an open commerce platform based on the Symfony php Framework and the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24745</guid>
    <pubDate>Wed, 09 Mar 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24745</strong></p>
  <p>Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish are not affected by this issue. This issue has been resolved in version 6.4.8.2. Users unable to upgrade should disable…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23599 – Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23599</guid>
    <pubDate>Fri, 28 Jan 2022 22:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23599</strong></p>
  <p>Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products.ATContentTypes prior to version 3.0.6 are vulnerable to reflected cross site scripting and open redirect when an attacker can get a compromised version of the image_view_fullscreen page in a cache, for example in Varnish. The technique is known as cache poisoning. Any later vis…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23959 – In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23959</guid>
    <pubDate>Wed, 26 Jan 2022 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23959</strong></p>
  <p>In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36740 – Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorizati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36740</guid>
    <pubDate>Wed, 14 Jul 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36740</strong></p>
  <p>Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-28543 – Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28543</guid>
    <pubDate>Tue, 16 Mar 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-28543</strong></p>
  <p>Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure or NULL pointer dereference can be triggered in Varnish Cache through the varni…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11653 – An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11653</guid>
    <pubDate>Wed, 08 Apr 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11653</strong></p>
  <p>An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20637 – An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20637</guid>
    <pubDate>Wed, 08 Apr 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20637</strong></p>
  <p>An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or V…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4090 – Varnish HTTP cache before 3.0.4: ACL bug</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4090</guid>
    <pubDate>Wed, 12 Feb 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4090</strong></p>
  <p>Varnish HTTP cache before 3.0.4: ACL bug</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15892 – An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15892</guid>
    <pubDate>Tue, 03 Sep 2019 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15892</strong></p>
  <p>An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it a Denial of Service attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-5763 – An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5763</guid>
    <pubDate>Mon, 19 Feb 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-5763</strong></p>
  <p>An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8807 – vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8807</guid>
    <pubDate>Thu, 16 Nov 2017 02:29:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8807</strong></p>
  <p>vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12425 – An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12425</guid>
    <pubDate>Fri, 04 Aug 2017 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12425</strong></p>
  <p>An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8852 – Varnish 3.x before 3.0.7, when used in certain stacked installations, allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8852</guid>
    <pubDate>Mon, 25 Apr 2016 14:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8852</strong></p>
  <p>Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-0345 – varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ director...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0345</guid>
    <pubDate>Thu, 08 May 2014 14:29:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-0345</strong></p>
  <p>varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, which allows local users to obtain sensitive information by reading the files.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4484 – Varnish before 3.0.5 allows remote attackers to cause a denial of service (child...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4484</guid>
    <pubDate>Fri, 01 Nov 2013 02:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4484</strong></p>
  <p>Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-0325 – Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0325</guid>
    <pubDate>Wed, 27 Mar 2013 21:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-0325</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2936 – The Command Line Interface (aka Server CLI or administration interface) in the m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2936</guid>
    <pubDate>Mon, 05 Apr 2010 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2936</strong></p>
  <p>The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-4488 – Varnish 2.0.6 writes data to a log file without sanitizing non-printable charact...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4488</guid>
    <pubDate>Wed, 13 Jan 2010 20:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-4488</strong></p>
  <p>Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.  NOTE: the vendor disputes the significance of this report, stating that "This is not a security problem in Varnish o…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4488">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
