logo

Fixing request smuggling vulnerabilities in Pingora OSS deployments

ID: cef3d98e-c2f6-5aa0-bf4c-c5e698a317ce

STIX ID: report--cef3d98e-c2f6-5aa0-bf4c-c5e698a317ce

Feed Name: Cloudflare Blog

Threat Score
50/100

Date Published: 2026-03-09

Date Updated: 2026-04-27

Author: Edward Wang

...
...

Cloudflare disclosed multiple HTTP/1.x request smuggling/desynchronization vulnerabilities in the open-source Pingora ingress proxy (three CVEs) that could allow bypassing proxy-layer controls, cross-user hijacking, and cache poisoning; fixes and RFC-stricter hardening were released in Pingora 0.8.0, Cloudflare’s CDN was not affected, and standalone Pingora deployments exposed to the Internet are urged to upgrade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.