Varnish HTTP Cache ACL Bypass Vulnerability

Vulnerability

An Access Control List (ACL) bypass vulnerability exists in Varnish HTTP Cache versions prior to 3.0.4. This vulnerability allows unauthorized users to bypass defined access controls, potentially leading to unauthorized actions or information disclosure.

Impact

Exploitation of this vulnerability can lead to unauthorized access or actions by bypassing ACL restrictions.

Added: Jun 22, 2026, 11:52 AM
Updated: Jun 22, 2026, 11:52 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.3
exploitability
8.9
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.