Vulnerabilities > Varnish Cache Project > Varnish Cache > 6.2.0

DATE CVE VULNERABILITY TITLE RISK
2025-03-21 CVE-2025-30346 HTTP Request Smuggling vulnerability in multiple products
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
4.8
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2021-07-14 CVE-2021-36740 HTTP Request Smuggling vulnerability in multiple products
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request.
6.5
2019-09-03 CVE-2019-15892 Reachable Assertion vulnerability in multiple products
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1.
7.5