
CVE-2026-40395 Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_head… https://www.cve.org/CVERecord?id=CVE-2026-40395
Post summary
The post announces that Varnish Enterprise versions prior to 6.0.16r12 are vulnerable to a workspace overflow denial of service in shared VCL via the headerplus.write_req0() function of vmod_head.

