Cloudflare Pingora Flaws Enable Request Smuggling and Cache Poisoning Attacks
ID: 26b4fd81-7d4c-5aed-bca5-6fd011b385d2
STIX ID: report--26b4fd81-7d4c-5aed-bca5-6fd011b385d2
Feed Name: GBHackers
Cloudflare disclosed three request-smuggling and cache-poisoning vulnerabilities in the open-source Pingora proxy (CVE-2026-2833, CVE-2026-2835, CVE-2026-2836) that can cause proxy-backend desynchronization, bypass proxy-layer protections and WAFs, enable session hijacking, and allow cache poisoning; Cloudflare clarified its own CDN is not affected. The advisory details three exploitation vectors—premature Upgrade handling, HTTP/1.0 framing misinterpretation, and insecure default cache keys—and urges operators to upgrade to Pingora 0.8.0, include host and scheme in cache keys, and monitor ingress proxy logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
