{"schema_version":"1.9.0","id":"CVE-2025-30346","published":"2025-03-21T00:00:00Z","modified":"2026-08-12T15:16:25.508745Z","aliases":["BIT-varnish-2025-30346"],"related":["openSUSE-SU-2025:14992-1","openSUSE-SU-2026:10751-1"],"details":"Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/varnishcache/varnish-cache","events":[{"introduced":"0"},{"fixed":"49168df457f8965fe5b3d257e95afaa2f41498c9"}],"database_specific":{"cpe":"cpe:2.3:a:varnish_cache_project:varnish_cache:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.6.2"}],"source":"CPE_RANGE"}}],"versions":["varnish-7.6.1","varnish-7.6.0","varnish-6.5.1","varnish-6.5.0","varnish-6.4.0","varnish-6.1.0","varnish-6.0.0","varnish-5.1.2","varnish-5.1.1","varnish-5.1.0","varnish-5.0.0","varnish-4.0.1","varnish-4.0.0","varnish-4.0.0-beta1","varnish-4.0.0-tp2","varnish-4.0.0-tp1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30346.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["23622748511810100298892430565560418682","218839734523592776867766468661275010437","164416863857509784494032526117345070744","223724184333599709384384874797774510966","197875613171327800308645167251626441464","263293726540262616557466597721550093620","271820512147372279692875200570924420053"],"threshold":0.9},"id":"CVE-2025-30346-367d39a1","signature_type":"Line","signature_version":"v1","source":"https://github.com/varnishcache/varnish-cache/commit/49168df457f8965fe5b3d257e95afaa2f41498c9","target":{"file":"bin/varnishtest/vtc_http.c"}},{"deprecated":false,"digest":{"function_hash":"320899585599011995335457946287409436056","length":956},"id":"CVE-2025-30346-99ef4ac7","signature_type":"Function","signature_version":"v1","source":"https://github.com/varnishcache/varnish-cache/commit/49168df457f8965fe5b3d257e95afaa2f41498c9","target":{"file":"bin/varnishtest/vtc_http2.c","function":"b64_settings"}},{"deprecated":false,"digest":{"line_hashes":["120248460162769918690912024032874919119","77104697107606013345318422003924957022","229700380975947820374920787836229443977","321786889213902170635439565983227828350","157674414179384749288192790946453512404","118266283243202144759254515689957791012","70255627731328964792477425442447516007"],"threshold":0.9},"id":"CVE-2025-30346-ac6a0e80","signature_type":"Line","signature_version":"v1","source":"https://github.com/varnishcache/varnish-cache/commit/49168df457f8965fe5b3d257e95afaa2f41498c9","target":{"file":"bin/varnishtest/vtc_http2.c"}},{"deprecated":false,"digest":{"function_hash":"329224240331914269285633393671409497276","length":968},"id":"CVE-2025-30346-b442b847","signature_type":"Function","signature_version":"v1","source":"https://github.com/varnishcache/varnish-cache/commit/49168df457f8965fe5b3d257e95afaa2f41498c9","target":{"file":"bin/varnishtest/vtc_http.c","function":"cmd_http_upgrade"}}],"vanir_signatures_modified":"2026-08-12T15:16:25Z"}}],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00027.html"},{"type":"WEB","url":"https://varnish-cache.org/security/VSV00015.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30346.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30346"}],"database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-444"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30346.json","unresolved_ranges":[{"extracted_events":[{"introduced":"7.5.0"},{"fixed":"7.6.2"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"7.5.0"},{"fixed":"7.6.2"}],"source":"CPE_FIELD"},{"extracted_events":[{"fixed":"7.6.2"},{"fixed":"6.0.13r10"}],"source":"DESCRIPTION"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}