Aller au contenu

Fiche vulnérabilité

CVE-2026-34475 : faille critique varnish-software varnish enterprise (CVSS 9.8)

Description

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
27 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • varnish-software varnish enterprise
  • vinyl-cache vinyl cache

Références

Rechercher une autre vulnérabilité dans la base CVE