Impact
A workspace buffer overflow was discovered in the .upper() and .lower() string methods used in VINYL Cache's VCL language. When a request contains a sufficiently long string, these methods can write beyond the allocated buffer, causing the VCL child process to segfault or trigger an assertion and then restart. Exploiting the flaw therefore results in a remote denial-of-service condition that destabilises the cache service. The vulnerability is a classic out-of-bounds write weakness described by CWE-787.
Affected Systems
The vulnerability affects Vinyl Cache releases prior to version 9.0.2. While the CNA list also names Varnish-Software’s Varnish Cache, the description references Vinyl Cache explicitly, so only Vinyl Cache versions before 9.0.2 are confirmed affected. There is no version range given for Varnish Cache.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score of less than 1% shows a very low likelihood that this flaw is currently being exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have prior knowledge of the target site’s VCL configuration and be able to craft a request that contains a string long enough to fill the remaining workspace while respecting normal HTTP request size limits. The attack vector is inferred to be remote, occurring through an ordinary HTTP request to the cache.
OpenCVE Enrichment