CVE-2025-30347: Varnish-Software Varnish Enterprise

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.

Affected products

Published 2025-03-21. Last modified 2026-06-17.