Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnish-modulesUpgrade varnish-develUpgrade varnishUpgrade varnish-docs | Jun 3, 2025 | May 13, 2025 |
| Alpine Linux | — | Upgrade varnish | Aug 20, 2025 | May 13, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 13, 2025 |
| Debian | — | Upgrade varnish | May 15, 2025 | May 15, 2025 |
| Oracle_linux | — | Upgrade varnish-docsUpgrade varnish-develUpgrade varnishUpgrade varnish-modules | Jun 3, 2025 | May 13, 2025 |
| Redhat_linux | — | Upgrade varnish-modules-debugsourceUpgrade varnishUpgrade varnish-modules-debuginfoUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-docs | May 30, 2025 | May 13, 2025 |
| Rocky_linux | — | Upgrade varnish-modulesUpgrade varnish-modules-debugsourceUpgrade varnishUpgrade varnish-develUpgrade varnish-modules-debuginfoUpgrade varnish-docs | Sep 9, 2025 | Jul 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub