Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9gq-cmcj-p62x

Опубликовано: 27 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

EPSS

Процентиль: 10%
0.00202
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-180

Связанные уязвимости

CVSS3: 5.4
ubuntu
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
redhat
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
nvd
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
debian
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in ...

EPSS

Процентиль: 10%
0.00202
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-180