MGASA-2026-0357

Source
https://advisories.mageia.org/MGASA-2026-0357.html
Import Source
https://advisories.mageia.org/MGASA-2026-0357.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0357
Upstream
  • CVE-2026-34475
Published
2026-09-01T03:06:53Z
Modified
2026-09-01T03:15:04Z
Summary
Updated varnish packages fix security vulnerabilities
Details

The updated packages fix security vulnerabilities: Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. (CVE-2026-34475) In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2. HTTP/2 support is disabled by default. (CVE-2026-50052)

References
Credits

Affected packages

Mageia:10 / varnish

Package

Name
varnish
Purl
pkg:rpm/mageia/varnish?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.0.2-2.mga10

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0357.json"

Mageia:9 / varnish

Package

Name
varnish
Purl
pkg:rpm/mageia/varnish?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.7.3-1.1.mga9

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0357.json"