Varnish Enterprise Denial-of-Service Vulnerability in Shared VCL Deployments

Vulnerability

A denial-of-service vulnerability has been identified in Varnish Enterprise versions 6.0.9r5 prior to 6.0.16r11. The issue arises in shared VCL deployments, where the 'headerplus.write_req0()' function from 'vmod_headerplus' can cause a 'workspace overflow'. This function updates the 'req0' with header fields from 'req', which is normally read-only. If too many headers are added, it can lead to a workspace overflow, triggering a daemon panic and crashing the Varnish server. This vulnerability can be exploited by malicious clients to cause a denial-of-service condition.

Impact

Exploitation of this vulnerability leads to a daemon panic, causing the Varnish Enterprise server to crash.

Remediation

Users are advised to upgrade Varnish Enterprise to version 6.0.16r12 or later and ensure that Varnish is restarted.

Added: Apr 12, 2026, 8:18 PM
Updated: Apr 12, 2026, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
7.6
remediation
7.7
relevance
5.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.