Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade varnish | Aug 8, 2025 | Mar 21, 2025 |
| Debian | — | Upgrade varnish | Apr 2, 2025 | Mar 21, 2025 |
| Freebsd | — | Upgrade varnish7 | Mar 24, 2025 | Mar 22, 2025 |
| Gentoo Linux | — | Upgrade www-servers/vinyl-cache. | Aug 26, 2026 | Aug 26, 2026 |
| Suse | — | Upgrade varnish-develUpgrade libvarnishapi3Upgrade varnish | Dec 5, 2025 | Apr 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub