CVE-2026-2833Patch(cloudflare / pingora)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cloudflare pingora systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, causing the proxy to pass through the rest of the bytes on the connection to a backend before the backend has accepted the upgrade. An attacker can thus directly forward a malicious payload after a request with an Upgrade header to that backend in a way that may be interpreted as a subsequent request header, bypassing proxy-level security controls and enabling cross-user session hijacking. Impact This vulnerability primarily affects standalone Pingora deployments where a Pingora proxy is exposed to external traffic. An attacker could exploit this to: * Bypass proxy-level ACL controls and WAF logic * Poison caches and upstream connections, causing subsequent requests from legitimate users to receive responses intended for smuggled requests * Perform cross-user attacks by hijacking sessions or smuggling requests that appear to originate from the trusted proxy IP Cloudflare's CDN infrastructure was not affected by this vulnerability, as ingress proxies in the CDN stack maintain proper HTTP parsing boundaries and do not prematurely switch to upgraded connection forwarding mode. Mitigation: Pingora users should upgrade to Pingora v0.8.0 or higher As a workaround, users may return an error on requests with the Upgrade header present in their request filter logic in order to stop processing bytes beyond the request header and disable downstream connection reuse.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pingora

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-09); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
pingora

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-09: 3Mentions · 2026-03-10: 2Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 2Technical Details · 2026-03-17: 103-0503-0603-0903-1003-17
Signal classification2 categories
Patch
562.5%
Disclosure
337.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-061
Patch1
2026-03-093
Disclosure2Patch1
2026-03-102
Patch2
2026-03-171
Patch1
Full discourse8 posts
  • Misbar | مسبار@MisbarSec
    Patch

    تلقت Cloudflare بلاغات حول ثغرات حرجة لتهريب طلبات HTTP/1.x ضمن إطار عمل Pingora مفتوح المصدر عند استخدامه كوكيل دخول (ingress proxy). تتضمن هذه الثغرات، المصنفة تحت (CVE-2026-2836, CVE-2026-2835, CVE-2026-2833)، إمكانية استغلال تضارب في تفسير الطلبات بين الوكيل والخادم الخلفي، مما قد يؤدي إلى تجاوز آليات الأمان وتسميم الذاكرة المؤقتة. لقد قامت Cloudflare بمعالجة هذه الثغرات وإصدار تحديثات أمنية. 🔗 للمزيد: https://blog.cloudflare.com/pingora-oss-smuggling-vulnerabilities/

    Post summary

    Cloudflare has released security updates to fix three critical request‑smuggling CVEs (2026‑2836, 2026‑2835, 2026‑2833) affecting its Pingora ingress proxy after reports of potential security bypass and cache poisoning.

    0002058
    65 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Cloudflare Pingora の脆弱性 CVE-2026-2833/2835/2836 が FIX:リクエスト・スマグリングなどに対応 https://iototsecnews.jp/2026/03/10/cloudflare-pingora-flaws-enable-request-smuggling-and-cache-poisoning-attacks/ Cloudflare が自社で開発しオープンソースとして公開している、Rust で書かれたプロキシ・フレームワーク Pingora で、リクエスト・スマグリングなどの深刻な脆弱性が修正されました。それらの問題の原因は、フロントエンド (外部からの受付) とバックエンド (実際の処理サーバ) の間で、”リクエストがどこで終わるか” という境界線の解釈を誤ってしまう、Pingora の設計にあります。ご利用のチームは、ご注意ください。 #Cloudflare #CVE20262833 #CVE20262835 #CVE20262836 #Pingora #Vulnerability

    Post summary

    Cloudflare’s Pingora framework vulnerabilities (CVE‑2026‑2833/2835/2836) have been fixed, addressing request smuggling and cache poisoning issues; no active exploitation or PoC details are reported.

    01000187
    484 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cloudflare Patches Critical Pingora Flaws Enabling Request Smuggling and Cache Poisoning Cloudflare released Pingora 0.8.0 to fix three critical vulnerabilities—CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836—that could let attackers bypass proxy ACLs and WAFs, smuggle hidden requests, and poison caches in standalone internet-exposed deployments. The issue matters because desync flaws in reverse proxies can quietly undermine core security controls and expose downstream applications to session hijacking and cross-user impact. 🎯 Target: Global/Internet-Exposed Proxies #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/cloudflare-pingora-vulnerabilities/

    Post summary

    The announcement focuses on Cloudflare’s release of a patch to address three critical Pingora vulnerabilities, providing technical details but no evidence of exploitation or PoC.

    1000038
    280 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2833 - HTTP Request Smuggling via Premature Upgrade Intel Report: https://ift.tt/db7ChUq

    Post summary

    The alert announces the existence of a CVE (HTTP Request Smuggling via Premature Upgrade) but offers no PoC, exploit code, patch, or evidence of live attacks.

    0001038
    343 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2833 An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request… https://www.cve.org/CVERecord?id=CVE-2026-2833 ----- Traducción: CVE-2026-2833 Se … http://infoflow.cloud`

    Post summary

    A new HTTP request smuggling vulnerability (CWE-444) has been disclosed affecting Pingora’s HTTP/1.1 upgrade handling, but no PoC, exploit, or patch details are provided.

    0000036
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2833 An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request… https://www.cve.org/CVERecord?id=CVE-2026-2833

    Post summary

    An HTTP request smuggling vulnerability (CWE‑444) has been identified in Pingora's handling of HTTP/1.1 connection upgrades.

    00000208
    56.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cloudflare patches Pingora request smuggling flaws that could bypass proxy defenses Cloudflare disclosed three Pingora OSS vulnerabilities—CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836—that can enable request smuggling, cache poisoning, and cross-user hijacking in Internet-exposed ingress proxy deployments, and fixed them in Pingora 0.8.0. This matters because vulnerable self-managed Pingora setups could let attackers slip past proxy-layer controls and desynchronize backend traffic even though Cloudflare’s own CDN was not affected. 🎯 Target: Global/Organizations Using Pingora OSS as an Ingress Proxy #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://blog.cloudflare.com/pingora-oss-smuggling-vulnerabilities/

    Post summary

    Cloudflare has released Pingora 0.8.0 to address three OSS vulnerabilities (CVE-2026-2833, 2835, 2836) that enable request smuggling, cache poisoning, and cross‑user hijacking, thereby mitigating risks for self‑managed ingress proxy deployments.

    0000080
    273 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    HTTP Request Smuggling via Premature Upgrade affects `pingora-core` (CVE-2026-2833). Mitigate by updating to version 0.8.0. Risks include cache poisoning and WAF bypass. #Pingora #SecurityAdvisory #HTTPRequestSmuggling https://www.pulsepatch.io/posts/cve-2026-2833-pingora-core-http-request-smuggling

    Post summary

    The advisory alerts users to CVE-2026-2833, a Premature Upgrade HTTP Request Smuggling vulnerability in pingora-core, and recommends upgrading to version 0.8.0 to mitigate risks such as cache poisoning and WAF bypass.

    0000038
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudflarepingora---

Explore more