VSV00018 Varnish Cache absolute form parsing deficiency

VSV00018 Varnish Cache absolute form parsing deficiency ¶ 2026-03-16 CVE-2026-34475 A deficiency in HTTP/1.1 request parsing can potentially be used for cache poisoning or authentication bypass, if the req.url VCL variable gets passed unchecked to a backend which accepts requests with absolute form URIs. The potential attack surface of this issue is limited to “root” URLs with a path of / as in example.com , but not example.com/whatever . We recommend to upgrade to a version which is not af

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论