CVE-2026-40394 Details
Description
Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurposed as stream zero. During the upgrade, a buffer allocation is made to reserve space to send frames to the client. This allocation would split the original workspace, and depending on the amount of prefetched data, the next fetch could perform a pipelining operation that would run out of workspace.
A denial-of-service vulnerability has been identified in Varnish Cache versions 9 prior to 9.0.1 and Varnish Enterprise versions 6.0.14r1 prior to 6.0.16r10. This vulnerability allows for a 'workspace overflow' denial-of-service condition, causing the daemon to panic, when certain amounts of prefetched data are handled during the upgrade from an HTTP/1 to an HTTP/2 session. The issue arises because the buffer allocation for the upgrade splits the original workspace, and depending on the amount of prefetched data, the next fetch could pipeline operations that exhaust the available workspace.
Users are advised to upgrade to Varnish Cache 9.0.1 or Varnish Enterprise 6.0.16r11. After upgrading, Varnish should be restarted to apply the changes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.varnish-software.com/security/VEV00002/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-670 | Always-Incorrect Control Flow Implementation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| varnish-software varnish enterprise | <= 6.0.15 6.0.16 r1 6.0.16 r10 6.0.16 r2 6.0.16 r3 6.0.16 r4 6.0.16 r5 6.0.16 r6 6.0.16 r7 6.0.16 r8 6.0.16 r9 |
CPE
Remediation
| |
| vinyl-cache vinyl cache | 9.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 12, 2026 | New CVE Received | [email protected] |