Vinyl-Cache records
3 published records for vendor vinyl-cache.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-670 Always-Incorrect Control Flow Implementation2
- CWE-180 Incorrect Behavior Order: Validate Before Canonicalize1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-34475No exploit | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / varnish-software · varnish enterprise · CWE-180 | Critical9.8 | — | 0.4% | Mar 27, 2026 |
30Monitor | CVE-2026-40396No exploit | Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger.vinyl-cache · vinyl cache · CWE-670 | High7.5 | — | 0.5% | Apr 12, 2026 |
30Monitor | CVE-2026-40394No exploit | Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certvarnish-software · varnish enterprise · CWE-670 | High7.5 | — | 0.4% | Apr 12, 2026 |
- CVE-2026-3447539Monitor
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of /
CriticalCVSS 9.8No exploitEPSS 0%varnish-software · varnish enterpriseMar 27, 2026
- CVE-2026-4039630Monitor
Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger.
HighCVSS 7.5No exploitEPSS 0%vinyl-cache · vinyl cacheApr 12, 2026
- CVE-2026-4039430Monitor
Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for cert
HighCVSS 7.5No exploitEPSS 0%varnish-software · varnish enterpriseApr 12, 2026