PT-2026-28633 · Varnish · Varnish Enterprise+1
CVE-2026-34475
·
Publicado
2026-03-27
·
Atualizado
2026-07-09
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Varnish Cache versions prior to 8.0.1
Varnish Enterprise versions prior to 6.0.16r12
Description
The software may improperly handle URLs with a path of '/' for HTTP/1.1 in certain unchecked request URL scenarios. This could potentially lead to cache poisoning or authentication bypass.
Recommendations
Update Varnish Cache to version 8.0.1 or later.
Update Varnish Enterprise to version 6.0.16r12 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Varnish Cache
Varnish Enterprise