CVE-2023-41104: Varnish-Software Varnish Enterprise
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access during base64 decoding, leading to both authentication bypass and information disclosure; however, the exact attack surface will depend on the particular VCL (Varnish Configuration Language) configuration in use.
Affected products
- Varnish-Software Varnish Enterprise: from 6.0.0, before 6.0.11 (fixed in 6.0.11); version 6.0.11 only
- Varnish-Software Vmod Digest: before 1.0.3 (fixed in 1.0.3)
Published 2023-08-23. Last modified 2026-06-17.