CVE-2025-30346
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD
Description
Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
Affected (26)
Products: Varnish Software: Varnish Enterprise · Varnish Cache Project: Varnish Cache
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0.11 r1 | |
| Before 7.6.2 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.