Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
References
| Link | Resource |
|---|---|
| https://vinyl-cache.org/security/VSV00018.html | Vendor Advisory Mitigation |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
22 Apr 2026, 19:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vinyl-cache.org/security/VSV00018.html - Vendor Advisory, Mitigation | |
| First Time |
Varnish-software varnish Enterprise
Vinyl-cache vinyl Cache Varnish-software Vinyl-cache |
|
| CPE | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r5:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r2:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r6:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r10:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r8:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r9:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r11:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r4:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r3:*:*:*:*:*:* cpe:2.3:a:vinyl-cache:vinyl_cache:*:*:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r7:*:*:*:*:*:* cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r1:*:*:*:*:*:* |
27 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-27 20:16
Updated : 2026-04-22 19:40
NVD link : CVE-2026-34475
Mitre link : CVE-2026-34475
CVE.ORG link : CVE-2026-34475
JSON object : View
Products Affected
vinyl-cache
- vinyl_cache
varnish-software
- varnish_enterprise
CWE
CWE-180
Incorrect Behavior Order: Validate Before Canonicalize
