#VU109043 Inconsistent interpretation of HTTP requests in Varnish Cache and Varnish Enterprise - CVE-2025-47905
Published: May 13, 2025 / Updated: May 21, 2025
Varnish Cache
Varnish Enterprise
Varnish Software
Description
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP/1 requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.