TYPO3 Varnishcache Extension Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing insecure direct object reference (IDOR) has been identified in the Varnishcache extension for TYPO3, prior to version 2.0.1. The issue arises in the Edge Site Includes (ESI) content element renderer component, which lacks an access check. This flaw enables unauthenticated users to render various content elements, potentially exposing internal content.

Impact

Exploitation of this vulnerability could lead to unauthorized access to and exposure of internal content elements through the ESI content element renderer.

Remediation

Users are advised to update the Varnishcache extension to version 2.0.1, available through the TYPO3 extension manager, Packagist, or the TYPO3 Extension Repository.

Added: Jun 22, 2026, 11:02 AM
Updated: Jun 22, 2026, 11:02 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
6.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.