Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40394

29
FAUCET Score

BRIEFING NOTE: CVE-2026-40394 OVERVIEW Varnish Cache versions 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 contain a workspace overflow vulnerability triggered during HTTP/2 session establishment. The flaw occurs when HTTP/1 prefetched data interacts with buffer allocations made during the HTTP/2 upgrade process, causing insufficient workspace for subsequent pipelining operations and resulting in daemon panic. SEVERITY This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and results in high availability impact through denial of service. The EPSS score of 0.00055 indicates this threat is currently exploited less frequently than most CVEs, though this represents a preliminary assessment. EXPLOITATION STATUS While not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, the vulnerability appears on the Active Hot List, suggesting active community attention and potential exploitation attempts. Organizations running the affected Varnish Cache or Enterprise versions should prioritize patching to 9.0.1 or 6.0.16r11 respectively, as network accessibility and ease of exploitation make this denial of service condition a material operational risk despite the moderate current exploitation prevalence.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.0.0, < 9.0.1CPE match
cpe:2.3:a:varnish-software:varnish_cache:*:technology_preview1:*:*:lts:*:*:*
<= 6.0.15CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:*
6.0.16CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r1:*:*:*:*:*:*
6.0.16CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r10:*:*:*:*:*:*
6.0.16CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 2nd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

docs.varnish-software.com / security/VEV00002
Vendor Advisory