Security, bugs & vulnerabilities
List of all Varnish CVEs#
| Versions | CVE | What |
|---|
| 5.x, 6.x, 7.x, 8.0 | N/A | VSV00018 Varnish Cache absolute form parsing deficiency |
| 5.x, 6.x, 7.x | CVE-2025-8671 | VSV00017 Varnish HTTP/2 Made You Reset Attack |
| 6.x, 7.x | CVE-2025-47905 | VSV00016 Request Smuggling Attack |
| 7.x | CVE-2025-30346 | VSV00015 Varnish HTTP/1 client-side desync vulnerability |
| 5.x, 6.x, 7.x | CVE-2024-30156 | VSV00014 Varnish HTTP/2 Broke Window Attack |
| 5.x, 6.x, 7.x | CVE-2023-44487 | VSV00013 Varnish HTTP/2 Rapid Reset Attack |
vmod_digest | CVE-2023-41104 | VSV00012 Base64 decoding vulnerability in vmod-digest |
| 6.x, 7.x | CVE-2022-45060 | VSV00011 Varnish HTTP/2 Request Forgery Vulnerability |
| 7.0, 7.1, 7.2 | CVE-2022-45059 | VSV00010 Varnish Request Smuggling Vulnerability |
| 7.0, 7.1 | CVE-2022-38150 | VSV00009 Varnish Denial of Service Vulnerability |
| < 7.0.2 | CVE-2022-23959 | VSV00008 Varnish HTTP/1 Request Smuggling Vulnerability |
| 6.0, 6.5, 6.6 | CVE-2021-36740 | VSV00007 Varnish HTTP/2 Request Smuggling Attack |
| (6.5) | CVE-2021-28543 | VSV00006 varnish-modules Denial of Service |
| 6.0, 6.2, 6.3 | CVE-2020-11653 | VSV00005 Varnish HTTP Proxy Protocol V2 Denial of Service |
| 6.0, 6.2, 6.3 | CVE-2019-20637 | VSV00004 Workspace information leak |
| 6.0, 6.2 | CVE-2019-15892 | VSV00003 DoS attack vector |
| 4.1, 5.2 | CVE-2017-8807 | VSV00002 Data leak - ‘-sfile’ Stevedore transient objects |
| 4.x, 5.x | CVE-2017-12425 | VSV00001 DoS vulnerability |
| < 3.0.5 | CVE-2013-4484 | DoS |
| <= 3.0.3 | CVE-2013-0345 | Local information leak |
| 2.0.6 | CVE-2009-4488 | Trophy hunting |
| < 2.1.0 | CVE-2009-2936 | Trophy hunting |
Reporting security vulnerabilities#
New security vulnerabilities can be reported by sending an e-mail to security@varnish-software.com or announce@vinyl-cache.org.