HTTP Request Smuggling Vulnerability in Pingora by Cloudflare
CVE-2026-2835
9.3CRITICAL
What is CVE-2026-2835?
A vulnerability has been identified in Pingora's handling of HTTP/1.0 request bodies and Transfer-Encoding values, which can lead to HTTP Request Smuggling attacks. This issue allows malicious actors to craft specially formatted requests that desynchronize Pingora’s request processing from backend servers. The impact includes potential bypass of proxy-based access controls, cache poisoning, and cross-user attacks through hijacked sessions. Users are advised to upgrade to Pingora version 0.8.0 or higher for mitigation and to adopt additional filtering measures to enhance security against malformed requests.
Affected Version(s)
https://github.com/cloudflare/pingora 0 < 0.8.0
