CVE-2026-50052
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
03/06/2026
Last modified:
03/06/2026
Description
In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync<br />
attack (request smuggling), which in turn can be used for cache poisoning,<br />
authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the<br />
feature parameter to contain +http2. HTTP/2 support is disabled by<br />
default.



