Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34475

Опубликовано: 27 мар. 2026
Источник: debian

Описание

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vinyl-cachenot-affectedpackage
varnishremovedpackage
varnishno-dsatrixiepackage
varnishno-dsabookwormpackage
varnishpostponedbullseyepackage

Примечания

  • https://vinyl-cache.org/security/VSV00018.html

Связанные уязвимости

CVSS3: 5.4
ubuntu
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
redhat
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
nvd
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
github
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.