Inconsistent interpretation of HTTP requests in Varnish Cache and Varnish Enterprise - CVE-2025-47905

 

Inconsistent interpretation of HTTP requests in Varnish Cache and Varnish Enterprise - CVE-2025-47905

Published: May 13, 2025 / Updated: May 21, 2025


Vulnerability identifier: #VU109043
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47905
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP/1 requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

Varnish Cache
Varnish Enterprise
Arch Linux
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
varnish-modules
varnish
varnish-devel
varnish-docs
varnish (Red Hat package)
varnish-debuginfo
varnish-debugsource
varnish-help

How to mitigate CVE-2025-47905

Install updates from vendor's website.

Varnish Cache - addressed in versions 6.0.14, 7.6.3, 7.7.1
Varnish Enterprise - update to 6.0.13r14
varnish-modules - update to 0.15.0-6
varnish - update to 6.0.13-1
varnish-devel - update to 6.0.13-1
varnish-docs - update to 6.0.13-1
varnish (Red Hat package) - addressed in versions 6.6.2-2.el9_0.4, 6.6.2-3.el9_2.3, 6.6.2-6.el9_6.1, 7.6.1-2.el10_0.1
varnish - update to 7.4.3-3
varnish-debuginfo - update to 7.4.3-3
varnish-debugsource - update to 7.4.3-3
varnish-devel - update to 7.4.3-3
varnish-help - update to 7.4.3-3
varnish - addressed in versions 7.5.0-4.fc41, 7.6.1-6.fc42
varnish - update to 7.7.1-1

External References

Related Security Bulletins