Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
References
| Link | Resource |
|---|---|
| https://vinyl-cache.org/security/VSV00018.html |
Configurations
No configuration.
History
27 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-27 20:16
Updated : 2026-03-30 13:26
NVD link : CVE-2026-34475
Mitre link : CVE-2026-34475
CVE.ORG link : CVE-2026-34475
JSON object : View
Products Affected
No product.
CWE
CWE-180
Incorrect Behavior Order: Validate Before Canonicalize
