Answer in brief
CVE-2026-93894 records a Unknown severity vulnerability in CISA ADP Vulnrichment. The current sources do not mark it as known exploited. The current feed maps Varnish-Software/Varnish Cache (generic), Vinyl-Cache/Vinyl Cache (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Varnish-Software/Varnish Cache (generic), Vinyl-Cache/Vinyl Cache (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Varnish-Software/Varnish Cachegeneric | >=9.0.0 <9.0.4 || >=0 <c5078ae575201b05ae8674a90ddb19ffe7f4b439 || 6.3.0 | 9.0.4, c5078ae575201b05ae8674a90ddb19ffe7f4b439 |
| Vinyl-Cache/Vinyl Cachegeneric | >=0 <9.0.2 || >=0 <90f5bacc14b2404e6cc349ba015f0f73b8515136 | 9.0.2, 90f5bacc14b2404e6cc349ba015f0f73b8515136 |
Published upstream
Sep 18, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 18, 2026
In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault or assert, and then restart. Effectively exploiting this vulnerability requires prior knowledge about the VCL in use and the ability to craft a request that contains a string that is long enough to fill the remaining workspace at the call site while staying under the different request size limits (http_req_size, http_req_hdr_len, etc.).
Quoted source text, attributed separately from HOL analysis.