Varnish-Software Varnish Enterprise vulnerabilities
4 known vulnerabilities affecting varnish-software/varnish_enterprise.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-40395MEDIUMCVSS 4.0≥ 6.0.9r5, < 6.0.16r122026-04-12
CVE-2026-40395 [MEDIUM] CWE-770 CVE-2026-40395: Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) f
Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writable from VCL). This is useful in the active VCL, after
cvelistv5nvd
CVE-2025-30347HIGHCVSS 7.5v6.0.13≥ 6, < 6.0.13r132025-03-21
CVE-2025-30347 [HIGH] CWE-125 CVE-2025-30347: Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an o
Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.
cvelistv5nvd
CVE-2025-30346MEDIUMCVSS 4.8v6.0.11v6.0.12+1 more2025-03-21
CVE-2025-30346 [MEDIUM] CWE-444 CVE-2025-30346: Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
nvd
CVE-2023-41104MEDIUMCVSS 6.5≥ 6.0.0, < 6.0.11v6.0.112023-08-23
CVE-2023-41104 [MEDIUM] CWE-119 CVE-2023-41104: libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-boun
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.
nvd