Client-Side Desync Vulnerability in Varnish Cache by Varnish Software
CVE-2025-47905
5.4MEDIUM
What is CVE-2025-47905?
A vulnerability in Varnish Cache allows for client-side desynchronization through HTTP/1 requests by improperly handling CRLF characters. This mismanagement can lead to attackers manipulating chunk boundaries, potentially resulting in data leakage or further exploits against applications relying on Varnish. Affected versions include those prior to 7.6.3 and 7.7.1, as well as Varnish Enterprise versions below 6.0.13r14.
Affected Version(s)
Varnish Cache 0 < 6.0.14 LTS
Varnish Cache 7.0.0 < 7.6.3
Varnish Cache 7.7.0 < 7.7.1
