HTTP Request Smuggling Vulnerability in Pingora by Cloudflare
CVE-2026-2835
What is CVE-2026-2835?
A vulnerability has been identified in Pingora's handling of HTTP/1.0 request bodies and Transfer-Encoding values, which can lead to HTTP Request Smuggling attacks. This issue allows malicious actors to craft specially formatted requests that desynchronize Pingora’s request processing from backend servers. The impact includes potential bypass of proxy-based access controls, cache poisoning, and cross-user attacks through hijacked sessions. Users are advised to upgrade to Pingora version 0.8.0 or higher for mitigation and to adopt additional filtering measures to enhance security against malformed requests.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
https://github.com/cloudflare/pingora 0 < 0.8.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
