CVE-2025-47905

NameCVE-2025-47905
DescriptionVarnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5918-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
varnish (PTS)bullseye6.5.1-1+deb11u3vulnerable
bullseye (security)6.5.1-1+deb11u4vulnerable
bookworm7.1.1-1.1vulnerable
bookworm (security)7.1.1-2+deb12u1fixed
trixie7.7.0-1vulnerable
sid7.7.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
varnishsourcebookworm7.1.1-2+deb12u1DSA-5918-1
varnishsource(unstable)7.7.0-2

Notes

https://varnish-cache.org/security/VSV00016.html
https://github.com/varnishcache/varnish-cache/commit/b5f1faba6e8d9848cfe0cba566986e7e5cc5f65b (varnish-7.7.1)
https://github.com/varnishcache/varnish-cache/commit/13904252859cf9848db5999b08c42d83a03ed812 (varnish-7.7.1)
https://github.com/varnishcache/varnish-cache/commit/3d9a9abff1c6734feea9d48d5852ccad7e7d0a42 (varnish-7.7.1)
https://github.com/varnishcache/varnish-cache/commit/00cb14931a53efafbdfec9843453fb1347bc9f59 (varnish-7.7.1)

Search for package or bug name: Reporting problems