CVE-2026-50052 Details
Description
In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2. HTTP/2 support is disabled by default.
A vulnerability exists in Vinyl Cache versions prior to 9.0.1 and Varnish Cache versions prior to 9.0.3, as well as in Varnish Cache releases from 7.6.0 up to and including 8.0.1, and in the Varnish Cache 6.0 LTS series from 6.0.14 up to and including 6.0.17. The issue arises from a deficiency in HTTP/2 request parsing, which can be exploited to launch a backend request desynchronization attack, commonly known as request smuggling. This exploitation can lead to cache poisoning, authentication bypass, and potentially allow for information disclosure and manipulation. The vulnerability is only exploitable if HTTP/2 support is enabled, which is not the default setting.
Users are advised to upgrade to Vinyl Cache 9.0.1 or Varnish Cache 9.0.3. For Varnish Cache, version 8.0.2 is also recommended. If an upgrade is not possible, HTTP/2 support can be disabled. For Varnish Cache, this can be done by removing `-p feature=+http2` from the `varnishd` startup parameters and changing the TLS offloader to no longer send the `h2` ALPN. In Vinyl Cache, HTTP/2 can be disabled by removing `-p feature=+http2` from the `vinyld` startup parameters. Additionally, VCL mitigations are available for both Vinyl Cache and Varnish Cache users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/01/9 | CVE | |
| https://vinyl-cache.org/security/VSV00019.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jul 1, 2026 | CVE Modified | CVE |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |