CVE-2026-50052

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
03/06/2026
Last modified:
03/06/2026

Description

In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync<br /> attack (request smuggling), which in turn can be used for cache poisoning,<br /> authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the<br /> feature parameter to contain +http2. HTTP/2 support is disabled by<br /> default.

References to Advisories, Solutions, and Tools