Loading
Generated remediation guidance and an executive summary. No account required.
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in certain circumstances involving -sfile Stevedore transient objects.
Cite this page
CVE-2017-8807. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2017-8807
Use CWE-119, Varnish-Cache vendor hub and Varnish product page to widen CVE-2017-8807 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-12425 and CVE-2013-4484 for nearby disclosures in the same product family.