CVE-2026-40395

29
FAUCET Score

VULNERABILITY OVERVIEW CVE-2026-40395 is a denial of service vulnerability affecting Varnish Enterprise versions prior to 6.0.16r12. The flaw exists in the headerplus.write_req0() function within vmod_headerplus, which fails to properly validate workspace boundaries when updating the underlying request object (req0) during shared VCL deployments. Malicious clients can exploit this by crafting requests with excessive header fields, triggering a workspace overflow that causes the Varnish daemon to panic and crash. SEVERITY ASSESSMENT The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack is trivial to execute due to low complexity, making it highly accessible to threat actors. While the impact is limited to availability (denial of service), the consequence is severe: complete server crash and service disruption. The FAUCET Risk Score of 48.0/100 indicates moderate organizational risk when considering broader threat context. EXPLOITATION STATUS The vulnerability is currently listed on the CISA KEV Catalog as Active, indicating active exploitation has been observed in the wild. However, EPSS scoring remains relatively low at 0.00055, suggesting limited prevalence in the broader threat landscape at this time. Organizations running Varnish Enterprise in production, particularly those utilizing shared VCL deployments through Varnish Controller, should prioritize immediate patching to 6.0.16r12 or later to mitigate active attack risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0.9r5, < 6.0.16r12CPE match
cpe:2.3:a:varnish-software:varnish_enterprise:*:r7:*:*:*:*:*:*
<= 6.0.15CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:*
6.0.16CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r1:*:*:*:*:*:*
6.0.16CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r10:*:*:*:*:*:*
6.0.16CPE matchmatch criteria
cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r11:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 2nd percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.