Varnish Enterprise是Varnish公司的一款高性能的缓存软件。用于处理高流量、优化业务。 Varnish Enterprise 6.0.16r12之前版本存在安全漏洞,该漏洞源于共享VCL中headerplus.write_req0函数更新底层req0时,如果修改后的req包含过多标头字段,可能导致工作空间溢出拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| varnish-software | Varnish Enterprise | 6.0.9r5 ~ 6.0.16r12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40396 | 4.0 MEDIUM | Varnish Cache 安全漏洞 |
| CVE-2026-40394 | 4.0 MEDIUM | Varnish Cache和Varnish Enterprise 安全漏洞 |
No comments yet