Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-34475: Varnish Cache: Unchecked URLs Can Bypass Security and Cache Data

CVE-2026-34475 · published 6 months ago
Summary

Varnish Cache versions before 8.0.1 and Varnish Enterprise versions before 6.0.16r12 may allow an attacker to bypass security checks and cache sensitive data. This could lead to unauthorized access to your website or compromised cache data. Update to the latest version to fix this issue.

What to do
  • Update debian rootio-varnish to version 7.1.1-2+deb12u1.root.io.7.
  • Update debian rootio-varnish to version 6.5.1-1+deb11u5.root.io.2.
  • Update debian varnish to version 7.1.1-2+deb12u1.aikido.8.
  • Update debian rootio-varnish to version 7.1.1-2+deb12u1.aikido.8.
  • Update vinyl-cache vinyl_cache to version 8.0.1 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian varnish All versions
Debian:12 debian varnish All versions
Debian:13 debian varnish All versions
Debian:14 debian varnish All versions
– varnish-software varnish_enterprise <= 6.0.15
6.0.16
cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:*
– vinyl-cache vinyl_cache < 8.0.1
cpe:2.3:a:vinyl-cache:vinyl_cache:*:*:*:*:*:*:*:*
Root:Debian:12 debian rootio-varnish < 7.1.1-2+deb12u1.root.io.7
< 7.1.1-2+deb12u1.aikido.8
Fix: upgrade to 7.1.1-2+deb12u1.root.io.7
Root:Debian:11 debian rootio-varnish < 6.5.1-1+deb11u5.root.io.2
Fix: upgrade to 6.5.1-1+deb11u5.root.io.2
Root:Debian:12 debian varnish < 7.1.1-2+deb12u1.aikido.8
Fix: upgrade to 7.1.1-2+deb12u1.aikido.8
Original advisory text
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or a...
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
Severity
9.8 Critical
CVSS 3.1: 5.4 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-180Incorrect Behavior Order: Validate Before Canonicalize
Timeline
Published27 Mar 2026
Updated25 Sep 2026
First seen27 Mar 2026
Track software like this
Free during beta