CVE-2026-93894

NameCVE-2026-93894
DescriptionIn Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault or assert, and then restart. Effectively exploiting this vulnerability requires prior knowledge about the VCL in use and the ability to craft a request that contains a string that is long enough to fill the remaining workspace at the call site while staying under the different request size limits (http_req_size, http_req_hdr_len, etc.).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148187

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
varnish (PTS)bookworm, bookworm (security)7.1.1-2+deb12u1vulnerable
trixie (security), trixie7.7.0-3+deb13u1vulnerable
vinyl-cache (PTS)forky, sid9.0.1-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
varnishsource(unstable)(unfixed)
vinyl-cachesource(unstable)(unfixed)1148187

Notes

https://vinyl-cache.org/security/VSV00020.html
Fixed by: https://code.vinyl-cache.org/vinyl-cache/vinyl-cache/commit/90f5bacc14b2404e6cc349ba015f0f73b8515136 (vinyl-cache-9.1.0)
Fixed by: https://code.vinyl-cache.org/vinyl-cache/vinyl-cache/commit/853d397f30753bce1587991fcf9193c63fb4d1eb (vinyl-cache-9.0.2)

Search for package or bug name: Reporting problems