VDB
ANCHORE-2025-47905
ANCHORE-2025-47905
PUBLISHED
Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| varnish-software | Varnish Cache | 0, 7.0.0, 7.7.0 |
Timeline
- May 13, 2025 CVE Published
- May 15, 2025 CVE Updated