https://vinyl-cache.org/organization/on_vinyl_cache_and_varnish_cache.html [ ] [ ] Skip to content Vinyl Cache Logo [ ] * Introduction[ ] * Security[ ] + Email addresses and GPG keys + VSV00018 Varnish Cache absolute form parsing deficiency + VSV00017 Varnish HTTP/2 Made You Reset Attack + VSV00016 Request Smuggling Attack + VSV00015 Varnish HTTP/1 client-side desync vulnerability + VSV00014 Varnish HTTP/2 Broke Window Attack + VSV00013 Varnish HTTP/2 Rapid Reset Attack + VSV00012 ... VSV00001[ ] o VSV00012 Base64 decoding vulnerability in vmod-digest o VSV00011 Varnish HTTP/2 Request Forgery Vulnerability o VSV00010 Varnish Request Smuggling Vulnerability o VSV00009 Varnish Denial of Service Vulnerability o VSV00008 Varnish HTTP/1 Request Smuggling Vulnerability o VSV00007 Varnish HTTP/2 Request Smuggling Attack o VSV00006 varnish-modules Denial of Service o VSV00005 Varnish HTTP Proxy Protocol V2 Denial of Service o VSV00004 Workspace information leak o VSV00003 DoS attack vector[ ] # VSV00003 DoS attack vector VCL mitigation o VSV00002 Data leak - '-sfile' Stevedore transient objects o VSV00001 DoS vulnerability * Releases & Downloads[ ] + Vinyl Cache 9.0.0 + Varnish Cache 8.0.1 + Varnish Cache 6.0.17 + Older Releases[ ] o Varnish Cache 8.0.0 o Varnish Cache 7.7.3 o Varnish Cache 7.6.5 o Varnish Cache 6.0.16 o Varnish Cache 7.7.2 o Varnish Cache 7.6.4 o Varnish Cache 6.0.15 o Varnish Cache 7.7.1 o Varnish Cache 7.6.3 o Varnish Cache 6.0.14 o Varnish Cache 7.7.0 o Varnish Cache 7.6.2 o Varnish Cache 7.6.1 o Varnish Cache 7.6.0 o Varnish Cache 7.5.0 o Varnish Cache 7.4.3 o Varnish Cache 7.4.2 o Varnish Cache 7.4.1 o Varnish Cache 7.4.0 o Varnish Cache 7.3.2 o Varnish Cache 7.3.1 o Varnish Cache 7.3.0 o Varnish Cache 7.2.1 o Varnish Cache 7.2.0 o Varnish Cache 7.1.2 o Varnish Cache 7.1.1 o Varnish Cache 7.1.0 o Varnish Cache 7.0.3 o Varnish Cache 7.0.2 o Varnish Cache 7.0.1 o Varnish Cache 7.0.0 o Varnish Cache 6.6.2 o Varnish Cache 6.6.1 o Varnish Cache 6.6.0 o Varnish Cache 6.5.2 o Varnish Cache 6.5.1 o Varnish Cache 6.5.0 o Varnish Cache 6.4.0 o Varnish Cache 6.3.2 o Varnish Cache 6.3.1 o Varnish Cache 6.3.0 o Varnish Cache 6.2.3 o Varnish Cache 6.2.2 o Varnish Cache 6.2.1 o Varnish Cache 6.2.0 o Varnish Cache 6.1.1 o Varnish Cache 6.1.0 o Varnish Cache 6.0.13 o Varnish Cache 6.0.12 o Varnish Cache 6.0.11 o Varnish Cache 6.0.10 o Varnish Cache 6.0.9 o Varnish Cache 6.0.8 o Varnish Cache 6.0.7 o Varnish Cache 6.0.6 o Varnish Cache 6.0.5 o Varnish Cache 6.0.4 o Varnish Cache 6.0.3 o Varnish Cache 6.0.2 o Varnish Cache 6.0.1 o Varnish Cache 6.0.0 o Varnish Cache 5.2.1 o Varnish Cache 5.2.0 o Varnish Cache 5.1.3 o Varnish Cache 5.1.2 o Varnish Cache 5.1.1 o Varnish Cache 5.0.0 o Varnish Cache 4.1.11 o Varnish Cache 4.1.10 o Varnish Cache 4.1.9 o Varnish Cache 4.1.8 o Varnish Cache 4.1.7 o Varnish Cache 4.1.6 o Varnish Cache 4.1.5 o Varnish Cache 4.1.4 o Varnish Cache 4.1.3 o Varnish Cache 4.1.2 o Varnish Cache 4.1.1 o Varnish Cache 4.1.0 o Varnish Cache 4.0.5 o Varnish Cache 4.0.4 o Varnish Cache 4.0.3 o Varnish Cache 4.0.2 o Varnish Cache 4.0.1 o Varnish Cache 4.0.0 o Varnish Cache 3.0.7 o Varnish Cache 3.0.6 o Varnish Cache 3.0.5 o Varnish Cache 3.0.4 o Varnish Cache 3.0.3 o Varnish Cache 3.0.2 o Varnish Cache 3.0.1 o Varnish Cache 3.0.0 o Varnish Cache 2.1.5 o Varnish Cache 2.1.4 o Varnish Cache 2.1.3 o Varnish Cache 2.1.2 o Varnish Cache 2.1.1 o Varnish Cache 2.1 o Varnish Cache 2.0.6 o Varnish Cache 2.0.5 o Varnish Cache 2.0.4 o Varnish Cache 2.0.3 o Varnish Cache 2.0.2 o Varnish Cache 2.0 o Varnish Cache 2.0.1 o Varnish Cache 1.1.2 o Varnish Cache 1.1.1 o Varnish Cache 1.1 o Varnish Cache 1.0.4 o Varnish Cache 1.0.3 o Varnish Cache 1.0.2 o Varnish Cache 1.0.1 o Varnish Cache 1.0 o Varnish Cache 0.9.1 o Varnish Cache 0.9 * News[ ] + VCOT: OpenTelemetry Instrumentation for Vinyl-Cache + Archive[ ] o 2024 o 2023 o 2022 o 2021 o 2020 o 2019 o 2018 o 2017 * Documentation[ ] * Tutorials[ ] + Sets in VMODs re2 and selector + Serving and updating files with VMOD file + Filter request- or response-headers with VMOD re2 sets * Tips & Tricks[ ] + VCL Snippets[ ] o 301/302 Redirects + Reading the varnishlog[ ] o Backend fetch failures and the FetchError tag + Migrating from old versions + Versions of the VCL language + Compiling on Alpine * Getting Help[ ] * Business[ ] * Modules (VMODs)[ ] + How to register your VMOD * Extras[ ] * Developer[ ] + Writing Documentation * Governance[*] + Bylaws of The Vinyl Cache Project (1.00)[ ] + The Bylaws + Minutes of meetings[ ] o 2026-02-23 Meeting of the General Assembly o 2025-10-29 Founding of the Vinyl Cache Association + 20 years old and it is time to get serious(er) + Vinyl Cache has left github + The Vinyl Cache Project has a New Identity + On Vinyl Cache and Varnish Cache Follow us on Mastodon Get updates of this homepage via RSS / Atom Our VM is sponsored by: NetAcute Sponsor Logo NetAcute Sponsor Logo ...and: Powered by FreeBSD Powered by FreeBSD Back to top On Vinyl Cache and Varnish CacheP 2026-04-08 We received helpful feedback that, as of April 2026, the situation around Vinyl Cache and Varnish Cache might not be easy to understand for users and distribution package maintainers alike. This is an attempt to help clarify. The backstory is that the former Varnish Cache FOSS project changed its name to Vinyl Cache. Please read 20 years old and it is time to get serious(er) if you have not already. This document has three parts. The first two parts are jointly approved by all of the Vinyl Cache Governing Board. The third part is an opinion by two members only. What happened since we announced the renameP Since we announced the above together with the Varnish Cache 8.0 release, the former Varnish Cache FOSS team, now Vinyl Cache Team, has been working hard on making the name change and many related changes happen until the 9.0 release on 2026-03-16. Here is a summary of events from our perspective: * The homepage https://vinyl-cache.org continues to serve all content previously available under https://varnish-cache.org, but the project name has been changed to Vinyl Cache and a new project identity (logo, mascot, color scheme) has been established. Care has been taken to preserve the name Varnish Cache for content referring to previous releases up to Varnish Cache 8.0. * The authoritative source repository, issues and pull requests have been migrated from GitHub to a self hosted forgejo instance on https://code.vinyl-cache.org (see Vinyl Cache has left github ). All old tickets have been preserved and issue numbering continues where it left off on GitHub. * The GitHub Varnish Cache Organization and all repositories have been archived. Repositories have a final commit updating the README and build scripts to point to the new repository, see for example The Varnish Cache README. * All references to Varnish in the Vinyl Cache source code have been replaced. See also information on the rename in the 9.0 release notes. As with the homepage, care has been taken to preserve the name Varnish Cache in historic documents as well as not to change valid references to copyright and authorship of Varnish Software. * Mailing lists have been renamed and moved to the vinyl-cache.org domain, but their historic content has been preserved. * Varnish Software has created a new repository with the name "Varnish" on GitHub, which continues to use the name "Varnish Cache". The last common commit of this new repository and what is now Vinyl Cache is 63806461a205a11da12deb21051f654e35acee9e (Vinyl Cache, Varnish Cache by Varnish Software), the next commit on the Varnish Software repository does not exist in Vinyl Cache. Note that GitHub fork tracking has not been used. * Varnish Software has forked the VTest project, which provides the varnishtest program. Likewise, fork tracking has not been used. * Varnish Software has created a new homepage for the relaunched Varnish Cache. * For https://www.varnish-cache.org/, the FOSS project had put in place a 301 redirect to https://vinyl-cache.org/ before the 9.0 launch. After the launch, which was agreed upon as the "demarcation point" for the completed rename and split, Varnish Software momentarily put up a simple page with "click here for Varnish Cache, click here for Vinyl Cache". At some point before 2024-04-02, Varnish Software has replaced it with a 301 redirect to https://www.varnish.org/index.html. Telling apart Varnish Cache and Vinyl CacheP So, confusingly, there is now Varnish Cache and Vinyl Cache, so which is which? What is Vinyl Cache?P We regard the Vinyl Cache FOSS project as the continuation of the former Varnish Cache FOSS project for the following reasons: * The maintainer team is unchanged and even continues to have a member employed by Varnish Software, based on a long standing agreement that each of the companies responsible for most of the core code contributions nominate one maintainer seat. The Vinyl Cache maintainer roles are currently taken by: + Poul Henning Kamp + Walid Boudebouda + Nils Goroll * The day-to-day operation of the Vinyl Cache project continues to function as before, with the same review processes, same bi-weekly bug wash, same main responsibilities etc. * As explained before, https://vinyl-cache.org/ has the same content as https://www.varnish-cache.org/ used to have, except for the rename. Everything is tracked in git. * Even the bug fix releases Varnish Cache 8.0.1 and Varnish Cache 6.0.17 were taken from branches 8.0 and 6.0 on the Vinyl Cache repository. For all practical purposes, we think it is fair to say that the Vinyl Cache Project is the former Varnish Cache FOSS project continued, just under a new name and with a governance model which we wanted for years. We said it would be a rename, and it is a rename What is the new Varnish Cache?P To quote https://www.varnish.org/index.html: Varnish Cache is a downstream distribution of the Vinyl Cache open source project, delivering a stable supported LTS release with additional tooling and features on top. The new Varnish Cache is governed by Varnish Software. The repository is located under the Varnish Software GitHub organization. The maintainers are Varnish Software Employees. The code base already contains commits which would be highly contended if proposed for merge into Vinyl Cache. This may be a regarded as a benefit, so this statement is meant to be informational, not qualitative. Varnish Software has a trademark policy which applies to Varnish Cache. Should you choose Vinyl Cache or Varnish Cache?P It is up to you and we want to be careful not to make a recommendation. But we are convinced that it is fair to state that the Vinyl Cache FOSS project is the continuation of the former Varnish Cache FOSS project and that, for all intends and purposes, the new Varnish Cache by Varnish Software is a new downstream project, with different governance, new code and different coding standards. Again, this can be seen as an advantage or not, this judgement is up to everyone to make for themselves. But the new Varnish Cache by Varnish Software project is by no means the continuation of the former Varnish Cache FOSS project. Vinyl Cache is that continuation. Our opinionP Above, we made an effort to only stick to verifiable facts. But we also have an opinion. This section only represents the opinion of slink and phk and is not shared by all of the Vinyl Cache Governing Board. You should think about Varnish/Vinyl as you do about MySQL/MariaDBP There are three distinct entities: 1. Varnish Cache before the corporate takeover Repos (archived) at: https://github.com/varnishcache/ varnish-cache 2. Vinyl Cache Repos (live) at: https://code.vinyl-cache.org/vinyl-cache/ vinyl-cache 3. Varnish Cache after the corporate takeover. Repos (live) at: https://github.com/varnish/varnish A and B are the same thing: The independent FOSS project you have known and relied on for twenty years, which only exists to create high-quality Free and Open Source Software, forced to change our name. C is a brand new fork of A, presenting as a FOSS project, but 100% controlled by a single for-profit corporation, using our old name, covered by a trademark policy. In other words: Exactly the same situation, as when Oracle bought MySQL and that FOSS project was forced to rename to MariaDB. History does not repeat, [...] it merely rhymes. - (probably) Theodor Reik Previous The Vinyl Cache Project has a New Identity Copyright (c) 2016-2026, The Varnish Cache and Vinyl Cache Contributors. Vinyl Cache Logo & Mascot: CC-BY 4.0 Rhubarbe.design Made with Sphinx and @pradyunsg's Furo On this page * On Vinyl Cache and Varnish Cache + What happened since we announced the rename + Telling apart Varnish Cache and Vinyl Cache o What is Vinyl Cache? o What is the new Varnish Cache? o Should you choose Vinyl Cache or Varnish Cache? + Our opinion o You should think about Varnish/Vinyl as you do about MySQL/MariaDB