Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and...
Moderate severity
Unreviewed
Published
May 14, 2025
to the GitHub Advisory Database
•
Updated May 29, 2025
Description
Published by the National Vulnerability Database
May 13, 2025
Published to the GitHub Advisory Database
May 14, 2025
Last updated
May 29, 2025
Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
References