Vinyl Cache is a narrowly scoped caching product with a small vulnerability footprint relative to the landscape. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vinyl Cache over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34475CRITICAL Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cac | Mar 27, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-40394HIGH Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setu | Apr 12, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-40396HIGH Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough | Apr 12, 2026 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vinyl Cache.
Media articles that mention a CVE ID that affects a product developed by Vinyl Cache — matched by CVE ID, not by vendor name.