BRIEFING NOTE: CVE-2026-40394 OVERVIEW Varnish Cache versions 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 contain a workspace overflow vulnerability triggered during HTTP/2 session establishment. The flaw occurs when HTTP/1 prefetched data interacts with buffer allocations made during the HTTP/2 upgrade process, causing insufficient workspace for subsequent pipelining operations and resulting in daemon panic. SEVERITY This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and results in high availability impact through denial of service. The EPSS score of 0.00055 indicates this threat is currently exploited less frequently than most CVEs, though this represents a preliminary assessment. EXPLOITATION STATUS While not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, the vulnerability appears on the Active Hot List, suggesting active community attention and potential exploitation attempts. Organizations running the affected Varnish Cache or Enterprise versions should prioritize patching to 9.0.1 or 6.0.16r11 respectively, as network accessibility and ease of exploitation make this denial of service condition a material operational risk despite the moderate current exploitation prevalence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.0.1CPE match | cpe:2.3:a:varnish-software:varnish_cache:*:technology_preview1:*:*:lts:*:*:* | ||
<= 6.0.15CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:* | ||
6.0.16CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r1:*:*:*:*:*:* | ||
6.0.16CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r10:*:*:*:*:*:* | ||
6.0.16CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.