CVE-2026-50052

EUVD-2026-34066
In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync
attack (request smuggling), which in turn can be used for cache poisoning,
authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the
feature parameter to contain +http2. HTTP/2 support is disabled by
default.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.77%
Debian logo
Debian Releases
Debian Product
Codename
varnish
bookworm
7.1.1-2+deb12u1
fixed
bookworm (security)
7.1.1-2+deb12u1
fixed
bullseye
6.5.1-1+deb11u3
fixed
bullseye (security)
6.5.1-1+deb11u5
fixed
trixie
7.7.0-3+deb13u1
fixed
trixie (security)
7.7.0-3+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
varnish
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage