Vulnerability Description
Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writable from VCL). This is useful in the active VCL, after amending req, to prepare a refined req0 before switching to a different VCL with the return (vcl(<label>)) action. This is for example how the Varnish Controller operates shared VCL deployments. If the amended req contained too many header fields for req0, this would have resulted in a workspace overflow that would in turn trigger a panic and crash the Varnish Enterprise server. This could be used as a Denial of Service attack vector by malicious clients.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Varnish-Software | Varnish Enterprise | <= 6.0.15 |
Related Weaknesses (CWE)
References
- https://docs.varnish-software.com/security/VEV00003/Vendor Advisory
FAQ
What is CVE-2026-40395?
CVE-2026-40395 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0...
How severe is CVE-2026-40395?
CVE-2026-40395 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40395?
Check the references section above for vendor advisories and patch information. Affected products include: Varnish-Software Varnish Enterprise.