CVE-2026-50052

NameCVE-2026-50052
DescriptionVSV00019
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6303-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
varnish (PTS)bullseye6.5.1-1+deb11u3fixed
bullseye (security)6.5.1-1+deb11u5fixed
bookworm, bookworm (security)7.1.1-2+deb12u1fixed
trixie7.7.0-3vulnerable
trixie (security)7.7.0-3+deb13u1fixed
forky, sid7.7.3-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
varnishsourcebullseye(not affected)
varnishsourcebookworm(not affected)
varnishsourcetrixie7.7.0-3+deb13u1DSA-6303-1
varnishsource(unstable)(unfixed)

Notes

[bookworm] - varnish <not-affected> (Vulnerable code not present, introduced in 7.6)
[bullseye] - varnish <not-affected> (Vulnerable code not present, introduced in 7.6)
https://vinyl-cache.org/security/VSV00019.html
https://code.vinyl-cache.org/vinyl-cache/vinyl-cache/commit/dfc27fb4e7bf110945f5c145ce95b8de14ead77f (master)
https://code.vinyl-cache.org/vinyl-cache/vinyl-cache/commit/037031d429e3d309ae66ebabff33aa591402f20e (6.0)

Search for package or bug name: Reporting problems