Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4101-1 | varnish security update |
EUVD |
EUVD-2025-7260 | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. |
Thu, 03 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 24 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Varnish-software
Varnish-software varnish Enterprise Varnish Cache Project Varnish Cache Project varnish Cache |
|
| CPEs | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r1:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r2:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r3:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r4:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r5:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r6:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.11:r7:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r1:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r2:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r3:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r4:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r5:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r6:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r7:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r8:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.12:r9:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r1:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r2:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r3:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r4:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r5:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r6:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r7:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r8:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.13:r9:*:*:*:*:*:* cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Varnish-software
Varnish-software varnish Enterprise Varnish Cache Project Varnish Cache Project varnish Cache |
Fri, 21 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | varnish: Client-Side Desynchronization in Varnish Cache | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 21 Mar 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-03T13:05:21.274Z
Reserved: 2025-03-21T00:00:00.000Z
Link: CVE-2025-30346
Updated: 2025-04-02T22:03:26.875Z
Status : Modified
Published: 2025-03-21T07:15:37.350
Modified: 2025-04-02T22:15:20.097
Link: CVE-2025-30346
OpenCVE Enrichment
No data.
Debian DLA
EUVD