Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unknown
7.5.0 (semver) before 7.6.2
affected
Description
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
Problem types
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Product status
7.5.0 (semver) before 7.6.2
References
lists.debian.org/debian-lts-announce/2025/03/msg00027.html
varnish-cache.org/security/VSV00015.html
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.