CVE-2025-47905
MEDIUM5.4EPSS 0.29%varnish - security update
發布日:2025/5/13修改日:2026/4/28
描述
Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.
受影響套件(4)
- Alpine/varnishfrom 0, < 7.6.3-r0
- Bitnami/varnishfrom 0, < 6.6.2, >= 7.0.0
- Debian/varnishfrom 0, < 6.5.1-1+deb11u5
- Debian/varnishfrom 0, < 6.5.1-1+deb11u5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N |
參考連結(6)
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2025-47905
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2025-47905
- WEBhttps://lists.debian.org/debian-lts-announce/2025/05/msg00040.html
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2025-47905
- WEBhttps://varnish-cache.org/security/VSV00016.html
- WEBhttp://www.openwall.com/lists/oss-security/2025/05/15/2