Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.40% | — | Varnish-software Varnish Enterprise | 12/4/2026 | 17/6/2026 | Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writable from VCL). This is… | |
| Analizada | Alta (7.5) | 0.40% | — | Varnish-software Varnish EnterpriseVinyl-cache Vinyl Cache | 12/4/2026 | 17/6/2026 | Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurposed as stream… | |
| Analizada | Crítica (9.8) | 0.37% | — | Varnish-software Varnish EnterpriseVinyl-cache Vinyl Cache | 27/3/2026 | 17/6/2026 | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. | |
| Aplazada | Media (5.4) | 0.36% | — | Varnish CacheAIVarnish-software Varnish EnterpriseAI | 13/5/2025 | 17/6/2026 | Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries. | |
| Analizada | Alta (7.5) | 0.34% | — | Varnish-software Varnish Enterprise | 21/3/2025 | 17/6/2026 | Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects. | |
| Modificada | Media (4.8) | 0.31% | — | Varnish-software Varnish EnterpriseVarnish Cache Project Varnish Cache | 21/3/2025 | 17/6/2026 | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. | |
| Modificada | Media (6.5) | 0.60% | — | Varnish-software Varnish EnterpriseVarnish-software Vmod Digest | 23/8/2023 | 17/6/2026 | libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language)… |