Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40396

28
FAUCET Score

CVE-2026-40396 is a denial of service vulnerability affecting Varnish Cache version 9.0.0, with a patch available in 9.0.1. The flaw stems from incomplete code integration during the port of Varnish Enterprise's non-blocking HTTP/2 architecture, specifically a missing workspace rollback in the HTTP/1 pipelining code path. An attacker can exploit this by sending sequential HTTP/1 requests across the timeout_linger and timeout_idle window to trigger workspace overflow, causing the Varnish daemon to panic and crash. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network attack vector requiring no authentication or user interaction, making it trivial to exploit remotely. The attack has no complexity requirements and results in complete availability impact through denial of service. While the EPSS score of 0.00016 indicates low prevalence in active exploitation, the vulnerability is listed on the CISA Known Exploited Vulnerabilities catalog and marked as active on the Hot List, suggesting elevated community attention and potential exploitation risk. Current exploitation status indicates this is not yet widely exploited in the wild based on EPSS metrics, though its active KEV listing warrants immediate patching. Organizations running Varnish Cache 9.0.0 should prioritize upgrading to version 9.0.1 or later to mitigate this high-severity availability risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.0.0, < 9.0.1CPE match
cpe:2.3:a:varnish-software:varnish_cache:*:technology_preview1:*:*:lts:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:vinyl-cache:vinyl_cache:9.0.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 8th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / varnish/varnish/issues/15
Issue Tracking
github.com / varnish/varnish/releases/tag/varnish-9.0.1
Product