Out-of-Bounds Read in Varnish Enterprise Can Expose Sensitive Data
CVE-2025-30347
7.5HIGH
What is CVE-2025-30347?
Varnish Enterprise prior to version 6.0.13r13 contains a vulnerability that allows remote attackers to exploit an out-of-bounds read condition. This issue arises during the handling of range requests on ephemeral MSE4 stevedore objects, potentially enabling unauthorized access to sensitive information stored in memory. Implementing the latest patches is crucial to mitigate this risk and safeguard your data.
Affected Version(s)
Varnish Enterprise 6 < 6.0.13r13
