PT-2025-12401 · Varnish+2 · Varnish Enterprise+3

CVE-2025-30346

·

Published

2025-03-21

·

Updated

2026-05-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Varnish Cache versions prior to 7.6.2 Varnish Enterprise versions prior to 6.0.13r10
Description The issue allows client-side desync via HTTP/1 requests.
Recommendations For Varnish Cache versions prior to 7.6.2, update to version 7.6.2 or later. For Varnish Enterprise versions prior to 6.0.13r10, update to version 6.0.13r10 or later.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16096
BIT-VARNISH-2025-30346
CVE-2025-30346
DLA-4101-1
DSA-5918-1
OESA-2025-1333
OPENSUSE-SU-2025:14992-1
OPENSUSE-SU-2026:10751-1

Affected Products

Debian
Red Os
Varnish Cache
Varnish Enterprise