Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libvarnishapi-dev", "binary_version": "7.7.0-1" }, { "binary_name": "libvarnishapi3", "binary_version": "7.7.0-1" }, { "binary_name": "libvarnishapi3-dbgsym", "binary_version": "7.7.0-1" }, { "binary_name": "varnish", "binary_version": "7.7.0-1" }, { "binary_name": "varnish-dbgsym", "binary_version": "7.7.0-1" }, { "binary_name": "varnish-doc", "binary_version": "7.7.0-1" } ] }