Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34475

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 5.4
CVSS3: 9.8
EPSS Низкий

Описание

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:*
Версия до 6.0.15 (включая)
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r1:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r10:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r11:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r2:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r3:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r4:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r5:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r6:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r7:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r8:*:*:*:*:*:*
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r9:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:vinyl-cache:vinyl_cache:*:*:*:*:*:*:*:*
Версия до 8.0.1 (исключая)

EPSS

Процентиль: 10%
0.00202
Низкий

5.4 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-180

Связанные уязвимости

CVSS3: 5.4
ubuntu
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
redhat
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS3: 5.4
debian
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in ...

CVSS3: 5.4
github
5 месяцев назад

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

EPSS

Процентиль: 10%
0.00202
Низкий

5.4 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-180