📦 Varnish Cache

by Varnish Cache Project

🔍 What is Varnish Cache?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-23959

CRITICAL CVSS 9.1 Jan 26, 2022

This CVE describes an HTTP request smuggling vulnerability in Varnish Cache and Varnish Enterprise. Attackers can exploit this to bypass security controls, poison caches, or hijack user sessions. Orga...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2025-30346

MEDIUM CVSS 5.4 Mar 21, 2025

This vulnerability allows attackers to perform client-side desync attacks via HTTP/1 requests against Varnish Cache and Varnish Enterprise. Attackers can poison caches and potentially bypass security ...