Inconsistent interpretation of HTTP requests in Varnish Cache and Varnish Enterprise - CVE-2025-47905
Published: May 13, 2025 / Updated: May 21, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP/1 requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Varnish Enterprise
Arch Linux
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
varnish-modules
varnish
varnish-devel
varnish-docs
varnish (Red Hat package)
varnish-debuginfo
varnish-debugsource
varnish-help
How to mitigate CVE-2025-47905
Varnish Enterprise - update to 6.0.13r14
varnish-modules - update to 0.15.0-6
varnish - update to 6.0.13-1
varnish-devel - update to 6.0.13-1
varnish-docs - update to 6.0.13-1
varnish (Red Hat package) - addressed in versions 6.6.2-2.el9_0.4, 6.6.2-3.el9_2.3, 6.6.2-6.el9_6.1, 7.6.1-2.el10_0.1
varnish - update to 7.4.3-3
varnish-debuginfo - update to 7.4.3-3
varnish-debugsource - update to 7.4.3-3
varnish-devel - update to 7.4.3-3
varnish-help - update to 7.4.3-3
varnish - addressed in versions 7.5.0-4.fc41, 7.6.1-6.fc42
varnish - update to 7.7.1-1
External References
Related Security Bulletins
- HTTP request smuggling in Varnish Cache and Varnish Enterprise
- Arch Linux update for varnish
- openEuler update for varnish
- Red Hat Enterprise Linux 8 update for the varnish:6 module
- Red Hat Enterprise Linux 8 update for the varnish:6 module
- Red Hat Enterprise Linux 9 update for varnish
- Red Hat Enterprise Linux 8 update for the varnish:6 module
- Red Hat Enterprise Linux 8 update for the varnish:6 module
- Red Hat Enterprise Linux 9 update for varnish
- Red Hat Enterprise Linux 9 update for varnish
- Red Hat Enterprise Linux 10 update for varnish
- Anolis OS update for varnish:6 module
- Fedora 42 update for varnish
- Fedora 41 update for varnish