{"id":"MGASA-2026-0357","summary":"Updated varnish packages fix security vulnerabilities","details":"The updated packages fix security vulnerabilities:\nVarnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in\ncertain unchecked req.url scenarios, mishandle URLs with a path of / for\nHTTP/1.1, potentially leading to cache poisoning or authentication\nbypass. (CVE-2026-34475)\nIn Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency\nin HTTP/2 request parsing can be exploited to launch a backend request\ndesync attack (request smuggling), which in turn can be used for cache\npoisoning, authentication bypass, or possibly even information\ndisclosure and manipulation. The attack vector only exists if HTTP/2\nsupport is enabled by setting the feature parameter to contain +http2.\nHTTP/2 support is disabled by default. (CVE-2026-50052)\n","modified":"2026-09-01T03:15:03.591065034Z","published":"2026-09-01T03:06:53Z","upstream":["CVE-2026-34475","CVE-2026-50052"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0357.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35703"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QTQ3IFV7A766BA4ZMWNVCZOAN3FGCW2J/"},{"type":"WEB","url":"https://vinyl-cache.org/security/VSV00018.html"},{"type":"WEB","url":"https://vinyl-cache.org/security/VSV00019.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W24WNWHXMWTWVX7NH65HHLBVOBMB3QGQ/"}],"affected":[{"package":{"name":"varnish","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/varnish?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.2-2.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0357.json"}},{"package":{"name":"varnish","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/varnish?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.7.3-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0357.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}