Home

Description

Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

PUBLISHED Reserved 2025-03-21 | Published 2025-03-21 | Updated 2025-04-03 | Assigner mitre




MEDIUM: 5.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Product status

Default status
unknown

7.5.0 (semver) before 7.6.2
affected

References

lists.debian.org/debian-lts-announce/2025/03/msg00027.html

varnish-cache.org/security/VSV00015.html

cve.org (CVE-2025-30346)

nvd.nist.gov (CVE-2025-30346)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.