Vulnerability Database

309,134

Total vulnerabilities in the database

CVE-2021-28543

Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure or NULL pointer dereference can be triggered in Varnish Cache through the varnish-modules header.append() and header.copy() functions. For some Varnish Configuration Language (VCL) files, this gives remote clients an opportunity to cause a Varnish Cache restart. A restart reduces overall availability and performance due to an increased number of cache misses, and may cause higher load on backend servers.

  • Published: Mar 16, 2021
  • Updated: Nov 16, 2025
  • CVE: CVE-2021-28543
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4
  • AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P