CVE-2026-34475 Details
Description
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
A vulnerability exists in Varnish Cache versions prior to 8.0.1 and Varnish Enterprise versions prior to 6.0.16r12. In certain scenarios where the 'req.url' variable is passed unchecked to a backend that accepts absolute form URIs, URLs with a path of '/' can be mishandled. This flaw in HTTP/1.1 request parsing may lead to cache poisoning or authentication bypass.
Users are advised to upgrade to Varnish Cache 8.0.1, Varnish Cache 6.0.17, or Varnish Enterprise 6.0.16r12 or later. If an upgrade is not possible, the issue can be mitigated by adding a specific VCL snippet to the top of the VCL, which has also been incorporated into the built-in VCL as a precaution.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vinyl-cache.org/security/VSV00018.html | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-180 | Incorrect Behavior Order: Validate Before Canonicalize | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| varnish-software varnish enterprise | <= 6.0.15 6.0.16 r1 6.0.16 r10 6.0.16 r11 6.0.16 r2 6.0.16 r3 6.0.16 r4 6.0.16 r5 6.0.16 r6 6.0.16 r7 6.0.16 r8 6.0.16 r9 |
CPE
Remediation
| |
| vinyl-cache vinyl cache | < 8.0.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |