Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
References
Configurations
No configuration.
History
15 May 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary |
|
13 May 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-13 22:15
Updated : 2025-05-16 14:43
NVD link : CVE-2025-47905
Mitre link : CVE-2025-47905
CVE.ORG link : CVE-2025-47905
JSON object : View
Products Affected
No product.
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')