Buffer Overflow Vulnerability in Vinyl Cache Product by Vinyl-Cache
CVE-2026-93894

2.3LOW

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93894?

A buffer overflow vulnerability has been discovered in the .upper() and .lower() string type methods of Vinyl Cache's VCL prior to version 9.0.2. This flaw can be exploited to initiate a remote denial of service (DoS) attack, causing the child process to crash and subsequently restart. Successful exploitation necessitates an understanding of the VCL in use and the ability to construct a specifically crafted request, ensuring that the string length is sufficient to fill the remaining workspace without exceeding defined request size limits.

Affected Version(s)

Varnish Cache 9.0.0 < 9.0.4

Varnish Cache 0

Varnish Cache 6.3.0 <= 8.0.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.