Switch language한국어
Back to the list

Fixing request smuggling vulnerabilities in Pingora OSS deployments

TL;DR AI

Key summary

2 min read
  1. Cloudflare received reports of HTTP/1.x request smuggling vulnerabilities in Pingora reports received in December 2025.

  2. Pingora released a patched version 0.8.0, pingora 0.8.0 includes fixes and hardening for the vulnerabilities.

  3. Vulnerabilities were assigned CVE identifiers, cVE-2026-2833, CVE-2026-2835, and CVE-2026-2836.

  4. Researcher reported the issues through a bug bounty program reporter identified as Rajat Raghav (xclow3n).

  5. Cloudflare CDN was not affected by the vulnerabilities investigation found no impact to Cloudflare CDN or customer traffic.

Read the original