CVE-2025-47905: Varnish-Software Varnish Cache
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
Affected products
- Varnish-Software Varnish Cache: before 6.0.14 LTS (fixed in 6.0.14 LTS); from 7.0.0, before 7.6.3 (fixed in 7.6.3); from 7.7.0, before 7.7.1 (fixed in 7.7.1)
Published 2025-05-13. Last modified 2026-06-17.