Vulnerabilities
Vulnerable Software
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
CVSS Score
5.4
EPSS Score
0.003
Published
2025-03-21
Varnish HTTP cache before 3.0.4: ACL bug
CVSS Score
7.5
EPSS Score
0.013
Published
2020-02-12
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
CVSS Score
7.5
EPSS Score
0.035
Published
2016-04-25
Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.
CVSS Score
5.0
EPSS Score
0.03
Published
2013-11-01


Contact Us

Shodan ® - All rights reserved