CVE-2026-40396 is a denial of service vulnerability affecting Varnish Cache version 9.0.0, with a patch available in 9.0.1. The flaw stems from incomplete code integration during the port of Varnish Enterprise's non-blocking HTTP/2 architecture, specifically a missing workspace rollback in the HTTP/1 pipelining code path. An attacker can exploit this by sending sequential HTTP/1 requests across the timeout_linger and timeout_idle window to trigger workspace overflow, causing the Varnish daemon to panic and crash. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network attack vector requiring no authentication or user interaction, making it trivial to exploit remotely. The attack has no complexity requirements and results in complete availability impact through denial of service. While the EPSS score of 0.00016 indicates low prevalence in active exploitation, the vulnerability is listed on the CISA Known Exploited Vulnerabilities catalog and marked as active on the Hot List, suggesting elevated community attention and potential exploitation risk. Current exploitation status indicates this is not yet widely exploited in the wild based on EPSS metrics, though its active KEV listing warrants immediate patching. Organizations running Varnish Cache 9.0.0 should prioritize upgrading to version 9.0.1 or later to mitigate this high-severity availability risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, < 9.0.1CPE match | cpe:2.3:a:varnish-software:varnish_cache:*:technology_preview1:*:*:lts:*:*:* | ||
9.0.0CPE matchmatch criteria | cpe:2.3:a:vinyl-cache:vinyl_cache:9.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.