Security Advisory

CVE-2025-47905

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-05-13 00:00:00
Last updated 2025-05-29 09:03:18
Assigner mitre
CVSS score 5.4
State PUBLISHED

Description

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.