Executive brief
Vinyl Cache, a web caching and acceleration service, contains a buffer overflow vulnerability in its string processing methods (.upper() and .lower()). An attacker can craft specially-sized requests to trigger a denial of service by crashing the cache worker process, causing service interruptions and requiring manual restarts.
Technical details
A workspace buffer overflow exists in the VCL .upper() and .lower() string type methods, allowing an unauthenticated remote attacker to overflow the workspace by sending a crafted request with a string sized to consume remaining workspace while respecting request size limits. Successful exploitation causes the child process to segfault or assert and restart. Exploitation requires knowledge of the deployed VCL configuration and careful crafting of the payload to stay within multiple size constraints (http_req_size, http_req_hdr_len, etc.).
Affected products
- Vinyl Cache Project Vinyl Cache before 9.0.2
- Varnish Software Varnish Cache up to and including 9.0.3
Timeline
- 2026-09-18: disclosed: CVE-2026-93894 published