{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0357",
  "published": "2026-09-01T03:06:53Z",
  "modified": "2026-09-01T01:53:11Z",
  "summary": "Updated varnish packages fix security vulnerabilities",
  "details": "The updated packages fix security vulnerabilities:\nVarnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in\ncertain unchecked req.url scenarios, mishandle URLs with a path of / for\nHTTP/1.1, potentially leading to cache poisoning or authentication\nbypass. (CVE-2026-34475)\nIn Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency\nin HTTP/2 request parsing can be exploited to launch a backend request\ndesync attack (request smuggling), which in turn can be used for cache\npoisoning, authentication bypass, or possibly even information\ndisclosure and manipulation. The attack vector only exists if HTTP/2\nsupport is enabled by setting the feature parameter to contain +http2.\nHTTP/2 support is disabled by default. (CVE-2026-50052)\n",
  "upstream": [
    "CVE-2026-34475",
    "CVE-2026-50052"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0357.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=35703"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QTQ3IFV7A766BA4ZMWNVCZOAN3FGCW2J/"
    },
    {
      "type": "WEB",
      "url": "https://vinyl-cache.org/security/VSV00018.html"
    },
    {
      "type": "WEB",
      "url": "https://vinyl-cache.org/security/VSV00019.html"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W24WNWHXMWTWVX7NH65HHLBVOBMB3QGQ/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "varnish",
        "purl": "pkg:rpm/mageia/varnish?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "8.0.2-2.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "varnish",
        "purl": "pkg:rpm/mageia/varnish?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.7.3-1.1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
