Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-docsUpgrade varnishUpgrade varnish-develUpgrade varnish-modules | Jun 3, 2025 | May 13, 2025 |
| Alpine Linux | — | Upgrade varnish | Aug 20, 2025 | May 13, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 13, 2025 |
| Debian | — | Upgrade varnish | May 15, 2025 | May 15, 2025 |
| Gentoo Linux | — | Upgrade www-servers/vinyl-cache. | Aug 26, 2026 | Aug 26, 2026 |
| Oracle_linux | — | Upgrade varnish-develUpgrade varnish-docsUpgrade varnishUpgrade varnish-modules | Jun 3, 2025 | May 13, 2025 |
| Redhat_linux | — | Upgrade varnishUpgrade varnish-modules-debugsourceUpgrade varnish-develUpgrade varnish-modules-debuginfoUpgrade varnish-modulesUpgrade varnish-docs | May 30, 2025 | May 13, 2025 |
| Rocky_linux | — | Upgrade varnish-modulesUpgrade varnishUpgrade varnish-modules-debugsourceUpgrade varnish-develUpgrade varnish-docsUpgrade varnish-modules-debuginfo | Sep 9, 2025 | Jul 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub