PT-2025-12401 · Varnish+2 · Varnish Cache+3

Published

2025-03-21

·

Updated

2026-05-11

·

CVE-2025-30346

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Varnish Cache versions prior to 7.6.2 Varnish Enterprise versions prior to 6.0.13r10
Description The issue allows client-side desync via HTTP/1 requests.
Recommendations For Varnish Cache versions prior to 7.6.2, update to version 7.6.2 or later. For Varnish Enterprise versions prior to 6.0.13r10, update to version 6.0.13r10 or later.

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16096
BIT-VARNISH-2025-30346
CVE-2025-30346
DLA-4101-1
DSA-5918-1
OESA-2025-1333
OPENSUSE-SU-2025:14992-1
OPENSUSE-SU-2026:10751-1

Affected Products

Debian
Red Os
Varnish Cache
Varnish Enterprise