logo

Resolving a request smuggling vulnerability in Pingora

ID: 902064d9-e886-5751-b7ae-ec2fb4bfbb29

STIX ID: report--902064d9-e886-5751-b7ae-ec2fb4bfbb29

Feed Name: Cloudflare Blog

Threat Score
55/100

Date Published: 2025-05-22

Date Updated: 2026-04-27

Author: Edward Wang

...
...

Cloudflare disclosed CVE-2025-4366: a request-smuggling vulnerability in the Pingora caching component used by a subset of free-plan CDN traffic. The bug allowed unread HTTP/1.1 request bodies on cache hits to be interpreted as the start of the next request, enabling header/URL injection; some origin servers could then return redirects to attacker-controlled hosts, exposing referrer URLs. Cloudflare disabled the vulnerable rollout, released a patch, invalidated cached assets, and advised Pingora users to upgrade to version 0.5.0 or later. No evidence of exploitation was found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.