CVE-2026-34475: Critical severity Varnish Software Varnish Cache vulnerability
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34475?
CVE-2026-34475 has a high severity rating due to its potential to lead to cache poisoning and authentication bypass.
How do I fix CVE-2026-34475?
The recommended fix for CVE-2026-34475 is to update Varnish Cache to version 8.0.1 or later, or Varnish Enterprise to version 6.0.16r12 or later.
What vulnerabilities are associated with CVE-2026-34475?
CVE-2026-34475 is associated with cache poisoning and authentication bypass vulnerabilities due to improper handling of certain URLs.
What versions of Varnish are affected by CVE-2026-34475?
CVE-2026-34475 affects Varnish Cache versions before 8.0.1 and Varnish Enterprise versions before 6.0.16r12.
How does CVE-2026-34475 impact web security?
CVE-2026-34475 can significantly compromise web security by allowing attackers to manipulate cache responses and bypass authentication mechanisms.