CVE-2026-40395
VULNERABILITY OVERVIEW CVE-2026-40395 is a denial of service vulnerability affecting Varnish Enterprise versions prior to 6.0.16r12. The flaw exists in the headerplus.write_req0() function within vmod_headerplus, which fails to properly validate workspace boundaries when updating the underlying request object (req0) during shared VCL deployments. Malicious clients can exploit this by crafting requests with excessive header fields, triggering a workspace overflow that causes the Varnish daemon to panic and crash. SEVERITY ASSESSMENT The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack is trivial to execute due to low complexity, making it highly accessible to threat actors. While the impact is limited to availability (denial of service), the consequence is severe: complete server crash and service disruption. The FAUCET Risk Score of 48.0/100 indicates moderate organizational risk when considering broader threat context. EXPLOITATION STATUS The vulnerability is currently listed on the CISA KEV Catalog as Active, indicating active exploitation has been observed in the wild. However, EPSS scoring remains relatively low at 0.00055, suggesting limited prevalence in the broader threat landscape at this time. Organizations running Varnish Enterprise in production, particularly those utilizing shared VCL deployments through Varnish Controller, should prioritize immediate patching to 6.0.16r12 or later to mitigate active attack risk.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.9r5, < 6.0.16r12CPE match | cpe:2.3:a:varnish-software:varnish_enterprise:*:r7:*:*:*:*:*:* | ||
<= 6.0.15CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:*:*:*:*:*:*:*:* | ||
6.0.16CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r1:*:*:*:*:*:* | ||
6.0.16CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r10:*:*:*:*:*:* | ||
6.0.16CPE matchmatch criteria | cpe:2.3:a:varnish-software:varnish_enterprise:6.0.16:r11:*:*:*:*:*:* |
CVSS Data
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
Exploit Intelligence
Social Chatter
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation
Remediation records are not available for this CVE.