Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade varnishUpgrade varnish-docsUpgrade varnish-develUpgrade varnish-modules | Jun 3, 2025 | May 13, 2025 |
| Alpine Linux | — | Upgrade varnish | Aug 20, 2025 | May 13, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 13, 2025 |
| Debian | — | Upgrade varnish | May 15, 2025 | May 15, 2025 |
| Gentoo Linux | — | Upgrade www-servers/vinyl-cache. | Aug 26, 2026 | Aug 26, 2026 |
| Oracle_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-docsUpgrade varnish-devel | Jun 3, 2025 | May 13, 2025 |
| Redhat_linux | — | Upgrade varnish-docsUpgrade varnish-modulesUpgrade varnish-develUpgrade varnish-modules-debuginfoUpgrade varnishUpgrade varnish-modules-debugsource | May 30, 2025 | May 13, 2025 |
| Rocky_linux | — | Upgrade varnishUpgrade varnish-modulesUpgrade varnish-modules-debugsourceUpgrade varnish-modules-debuginfoUpgrade varnish-develUpgrade varnish-docs | Sep 9, 2025 | Jul 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub