# CVE-2026-34475

## Summary

- **CVE ID:** CVE-2026-34475
- **Severity:** MEDIUM
- **CVSS Score:** 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **CWE:** CWE-180
- **Published:** Mar 27, 2026
- **Last Modified:** Mar 27, 2026

## Description

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

## Affected Products

- varnish-software — Varnish Cache (0)
- varnish-software — Varnish Cache (7.0.0)

## References

- [CNA](https://vinyl-cache.org/security/VSV00018.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._