Known vulnerabilities in varnish (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:varnish_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 4
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting varnish (Red Hat package) varnish (Red Hat package) is affected by 4 known vulnerabilities: 1 high, 3 medium Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU109043 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-47905
CWE-444 Medium
No
No
6.6.2-2.el9_0.4, 6.6.2-3.el9_2.3, 6.6.2-6.el9_6.1, 7.6.1-2.el10_0.1 13.05.2025 SB2025051363
SB20250521114
SB2025052335
and 11 more
#VU88221 - Resource exhaustion
CVE-2024-30156
CWE-400 Medium
No
No
6.6.2-2.el9_0.3, 6.6.2-3.el9_2.2, 6.6.2-4.el9_3.1 09.04.2024 SB2024040916
SB2024040925
SB2024040926
and 10 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
6.6.2-2.el9_0.2, 6.6.2-3.el9_2.1 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 652 more
#VU69128 - Server-Side Request Forgery (SSRF)
CVE-2022-45060
CWE-918 Medium
No
No
6.6.2-2.el9_0.1, 6.6.2-2.el9_1.1 08.11.2022 SB2022110886
SB2022112827
SB2022112828
and 17 more