Client-Side Desync Vulnerability in Varnish Cache by Varnish Software
CVE-2025-47905

5.4MEDIUM

Key Information:

Vendor
CVE Published:
13 May 2025

What is CVE-2025-47905?

A vulnerability in Varnish Cache allows for client-side desynchronization through HTTP/1 requests by improperly handling CRLF characters. This mismanagement can lead to attackers manipulating chunk boundaries, potentially resulting in data leakage or further exploits against applications relying on Varnish. Affected versions include those prior to 7.6.3 and 7.7.1, as well as Varnish Enterprise versions below 6.0.13r14.

Affected Version(s)

Varnish Cache 0 < 6.0.14 LTS

Varnish Cache 7.0.0 < 7.6.3

Varnish Cache 7.7.0 < 7.7.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.