CVE-2026-34475
EUVD-2026-1680127.03.2026, 20:16
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| varnish-software | varnish_enterprise | 𝑥 ≤ 6.0.15 |
| varnish-software | varnish_enterprise | 6.0.16:r1 |
| varnish-software | varnish_enterprise | 6.0.16:r10 |
| varnish-software | varnish_enterprise | 6.0.16:r11 |
| varnish-software | varnish_enterprise | 6.0.16:r2 |
| varnish-software | varnish_enterprise | 6.0.16:r3 |
| varnish-software | varnish_enterprise | 6.0.16:r4 |
| varnish-software | varnish_enterprise | 6.0.16:r5 |
| varnish-software | varnish_enterprise | 6.0.16:r6 |
| varnish-software | varnish_enterprise | 6.0.16:r7 |
| varnish-software | varnish_enterprise | 6.0.16:r8 |
| varnish-software | varnish_enterprise | 6.0.16:r9 |
| vinyl-cache | vinyl_cache | 𝑥 < 8.0.1 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration