CVE-2026-34475Incorrect Behavior Order: Validate Before Canonicalize in Varnish Cache

Severity
5.4MEDIUMNVD
EPSS
0.0%
top 86.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27

Description

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.7

Affected Packages1 packages

CVEListV5varnish-software/varnish_cache7.0.08.0.1+1

🔴Vulnerability Details

3
GHSA
GHSA-m9gq-cmcj-p62x: Varnish Cache before 82026-03-27
OSV
CVE-2026-34475: Varnish Cache before 82026-03-27
CVEList
CVE-2026-34475: Varnish Cache before 82026-03-27

📋Vendor Advisories

2
Red Hat
Varnish Cache: Varnish Cache and Varnish Enterprise: Cache poisoning and authentication bypass via unchecked URL handling2026-03-27
Debian
CVE-2026-34475: varnish - Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain u...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-34475 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-34475 — Varnish Cache vulnerability | cvebase