logo

Cloudflare Pingora Vulnerabilities Allows Request Smuggling & Cache Poisoning Attacks

ID: a3a42910-bee1-5070-a852-9e94ef217e81

STIX ID: report--a3a42910-bee1-5070-a852-9e94ef217e81

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Abinaya

...
...

Cloudflare published an advisory and released Pingora 0.8.0 to patch three critical vulnerabilities that allow HTTP request smuggling, HTTP desync attacks, and default cache key poisoning in standalone Pingora deployments; these flaws can bypass proxy ACLs/WAFs, hijack sessions, and cause cross-origin cache collisions, and Cloudflare recommends immediate upgrades and configuration mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.