CVE-2025-30346
21.03.2025, 07:15
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
Vendor | Product | Version |
---|---|---|
varnish-software | varnish_enterprise | 6.0.11:r1 |
varnish-software | varnish_enterprise | 6.0.11:r2 |
varnish-software | varnish_enterprise | 6.0.11:r3 |
varnish-software | varnish_enterprise | 6.0.11:r4 |
varnish-software | varnish_enterprise | 6.0.11:r5 |
varnish-software | varnish_enterprise | 6.0.11:r6 |
varnish-software | varnish_enterprise | 6.0.11:r7 |
varnish-software | varnish_enterprise | 6.0.12:r1 |
varnish-software | varnish_enterprise | 6.0.12:r2 |
varnish-software | varnish_enterprise | 6.0.12:r3 |
varnish-software | varnish_enterprise | 6.0.12:r4 |
varnish-software | varnish_enterprise | 6.0.12:r5 |
varnish-software | varnish_enterprise | 6.0.12:r6 |
varnish-software | varnish_enterprise | 6.0.12:r7 |
varnish-software | varnish_enterprise | 6.0.12:r8 |
varnish-software | varnish_enterprise | 6.0.12:r9 |
varnish-software | varnish_enterprise | 6.0.13:r1 |
varnish-software | varnish_enterprise | 6.0.13:r2 |
varnish-software | varnish_enterprise | 6.0.13:r3 |
varnish-software | varnish_enterprise | 6.0.13:r4 |
varnish-software | varnish_enterprise | 6.0.13:r5 |
varnish-software | varnish_enterprise | 6.0.13:r6 |
varnish-software | varnish_enterprise | 6.0.13:r7 |
varnish-software | varnish_enterprise | 6.0.13:r8 |
varnish-software | varnish_enterprise | 6.0.13:r9 |
varnish_cache_project | varnish_cache | 𝑥 < 7.6.2 |
𝑥
= Vulnerable software versions

Debian Releases
Vulnerability Media Exposure