Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-34475: Varnish Cache: Unchecked URLs Can Bypass Security and Cache Data
CVE-2026-34475 · published 6 months ago
Summary
Varnish Cache versions before 8.0.1 and Varnish Enterprise versions before 6.0.16r12 may allow an attacker to bypass security checks and cache sensitive data. This could lead to unauthorized access to your website or compromised cache data. Update to the latest version to fix this issue.
What to do
- Update debian rootio-varnish to version 7.1.1-2+deb12u1.root.io.7.
- Update debian rootio-varnish to version 6.5.1-1+deb11u5.root.io.2.
- Update debian varnish to version 7.1.1-2+deb12u1.aikido.8.
- Update debian rootio-varnish to version 7.1.1-2+deb12u1.aikido.8.
- Update vinyl-cache vinyl_cache to version 8.0.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | varnish | All versions |
| Debian:12 | debian | varnish | All versions |
| Debian:13 | debian | varnish | All versions |
| Debian:14 | debian | varnish | All versions |
| – | varnish-software | varnish_enterprise |
<= 6.0.15 6.0.16 cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:* |
| – | vinyl-cache | vinyl_cache |
< 8.0.1 cpe:2.3:a:vinyl-cache:vinyl_cache:*:*:*:*:*:*:*:* |
| Root:Debian:12 | debian | rootio-varnish |
< 7.1.1-2+deb12u1.root.io.7 < 7.1.1-2+deb12u1.aikido.8 Fix: upgrade to 7.1.1-2+deb12u1.root.io.7
|
| Root:Debian:11 | debian | rootio-varnish |
< 6.5.1-1+deb11u5.root.io.2 Fix: upgrade to 6.5.1-1+deb11u5.root.io.2
|
| Root:Debian:12 | debian | varnish |
< 7.1.1-2+deb12u1.aikido.8 Fix: upgrade to 7.1.1-2+deb12u1.aikido.8
|
Original advisory text
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or a...
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
References
Severity
9.8
Critical
CVSS 3.1: 5.4 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-180Incorrect Behavior Order: Validate Before Canonicalize
Timeline
Published27 Mar 2026
Updated25 Sep 2026
First seen27 Mar 2026
Track software like this
Free during beta