CVE-2026-40396 Details
Description
Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linger) and resume traffic before the session is closed (timeout_idle) sending more than one request at once to trigger a pipelining operation between requests. This vulnerability affecting Varnish Cache 9.0.0 emerged from a port of the Varnish Enterprise non-blocking architecture for HTTP/2. New code was needed to adapt to a more recent workspace API that formalizes the pipelining operation. In addition to the workspace change on the Varnish Cache side, other differences created merge conflicts, like partial support for trailers in Varnish Enterprise. The conflict resolution missed one code path configuring pipelining to perform a complete workspace rollback, losing the guarantee that prefetched data would fit inside workspace_client during the transition from one request to the next. This can result in a workspace overflow, triggering a panic and crashing the Varnish server.
A denial-of-service vulnerability has been identified in Varnish Cache 9.0.0, allowing for a "workspace overflow" that causes the daemon to panic and crash. This issue arises after the `timeout_linger` period, when a malicious client can send an HTTP/1 request, wait for the session to release its worker thread, and then resume traffic before the session is fully closed. By sending multiple requests simultaneously, the client can trigger a pipelining operation that overwhelms the server's workspace, leading to a crash. This vulnerability is a result of conflicts during the adaptation of Varnish Enterprise's non-blocking HTTP/2 architecture to Varnish Cache, where a critical code path was missed, allowing the overflow to occur.
Users can upgrade to Varnish Cache 9.0.1, which addresses this vulnerability by fixing the workspace handling for HTTP/1 and HTTP/2 sessions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/varnish/varnish/issues/15 | [email protected] | Issue Tracking |
| https://github.com/varnish/varnish/releases/tag/varnish-9.0.1 | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-670 | Always-Incorrect Control Flow Implementation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vinyl-cache vinyl cache | 9.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 12, 2026 | New CVE Received | [email protected] |