HTTP Request Smuggling Vulnerability in Pingora by Cloudflare
CVE-2026-2835

9.3CRITICAL

Key Information:

Vendor

Cloudflare

Vendor
CVE Published:
4 March 2026

What is CVE-2026-2835?

A vulnerability has been identified in Pingora's handling of HTTP/1.0 request bodies and Transfer-Encoding values, which can lead to HTTP Request Smuggling attacks. This issue allows malicious actors to craft specially formatted requests that desynchronize Pingora’s request processing from backend servers. The impact includes potential bypass of proxy-based access controls, cache poisoning, and cross-user attacks through hijacked sessions. Users are advised to upgrade to Pingora version 0.8.0 or higher for mitigation and to adopt additional filtering measures to enhance security against malformed requests.

Affected Version(s)

https://github.com/cloudflare/pingora 0 < 0.8.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rajat Raghav (xclow3n)
.