HTTP Request Smuggling Vulnerability in Pingora by Cloudflare
CVE-2026-2835

9.3CRITICAL

Key Information:

Vendor

Cloudflare

Vendor
CVE Published:
4 March 2026

What is CVE-2026-2835?

A vulnerability has been identified in Pingora's handling of HTTP/1.0 request bodies and Transfer-Encoding values, which can lead to HTTP Request Smuggling attacks. This issue allows malicious actors to craft specially formatted requests that desynchronize Pingora’s request processing from backend servers. The impact includes potential bypass of proxy-based access controls, cache poisoning, and cross-user attacks through hijacked sessions. Users are advised to upgrade to Pingora version 0.8.0 or higher for mitigation and to adopt additional filtering measures to enhance security against malformed requests.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

https://github.com/cloudflare/pingora 0 < 0.8.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rajat Raghav (xclow3n)
.