Description
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault or assert, and then restart. Effectively exploiting this vulnerability requires prior knowledge about the VCL in use and the ability to craft a request that contains a string that is long enough to fill the remaining workspace at the call site while staying under the different request size limits (http_req_size, http_req_hdr_len, etc.).
Published: 2026-09-18
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A workspace buffer overflow was discovered in the .upper() and .lower() string methods used in VINYL Cache's VCL language. When a request contains a sufficiently long string, these methods can write beyond the allocated buffer, causing the VCL child process to segfault or trigger an assertion and then restart. Exploiting the flaw therefore results in a remote denial-of-service condition that destabilises the cache service. The vulnerability is a classic out-of-bounds write weakness described by CWE-787.

Affected Systems

The vulnerability affects Vinyl Cache releases prior to version 9.0.2. While the CNA list also names Varnish-Software’s Varnish Cache, the description references Vinyl Cache explicitly, so only Vinyl Cache versions before 9.0.2 are confirmed affected. There is no version range given for Varnish Cache.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity, and the EPSS score of less than 1% shows a very low likelihood that this flaw is currently being exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have prior knowledge of the target site’s VCL configuration and be able to craft a request that contains a string long enough to fill the remaining workspace while respecting normal HTTP request size limits. The attack vector is inferred to be remote, occurring through an ordinary HTTP request to the cache.

Generated by OpenCVE AI on September 19, 2026 at 16:34 UTC.

Remediation

Vendor Solution

Update to unaffected Version


Vendor Workaround

replace the .upper() and .lower() VCL type method calls by their respective vmod_std counterparts: std.toupper() and std.tolower().


OpenCVE Recommended Actions

  • Update Vinyl Cache to an unaffected version such as 9.0.2 or later.
  • If a patch is unavailable, replace all .upper() and .lower() VCL calls with the vmod_std equivalents std.toupper() and std.tolower().
  • Verify that the varnish configuration no longer invokes the vulnerable methods and that the cache service remains stable.
  • Monitor system logs for de‑segmentation faults or restart events that might indicate exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Varnish-software
Varnish-software varnish Cache
Vinyl-cache
Vinyl-cache vinyl Cache
Vendors & Products Varnish-software
Varnish-software varnish Cache
Vinyl-cache
Vinyl-cache vinyl Cache

Sat, 19 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Workspace Buffer Overflow in Vinyl Cache .upper() and .lower() Methods Leading to Remote Denial of Service

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault or assert, and then restart. Effectively exploiting this vulnerability requires prior knowledge about the VCL in use and the ability to craft a request that contains a string that is long enough to fill the remaining workspace at the call site while staying under the different request size limits (http_req_size, http_req_hdr_len, etc.).
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:L/U:Clear'}


Subscriptions

Varnish-software Varnish Cache
Vinyl-cache Vinyl Cache
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-19T14:01:28.211Z

Reserved: 2026-09-18T20:30:04.310Z

Link: CVE-2026-93894

cve-icon Vulnrichment

Updated: 2026-09-19T13:59:31.404Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T21:18:49.297

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-93894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:00:08Z

Weaknesses