Misbar | مسبار[verified]@MisbarSecPatch
Cloudflare has released security updates to fix three critical request‑smuggling CVEs (2026‑2836, 2026‑2835, 2026‑2833) affecting its Pingora ingress proxy after reports of potential security bypass and cache poisoning.
ThreatSynop[verified]@ThreatSynopPatch
The announcement focuses on Cloudflare’s release of a patch to address three critical Pingora vulnerabilities, providing technical details but no evidence of exploitation or PoC.
ThreatSynop[verified]@ThreatSynopPatch
Cloudflare has released Pingora 0.8.0 to address three OSS vulnerabilities (CVE-2026-2833, 2835, 2836) that enable request smuggling, cache poisoning, and cross‑user hijacking, thereby mitigating risks for self‑managed ingress proxy deployments.
iototsecnews@iototsecnewsPatch
Cloudflare’s Pingora framework vulnerabilities (CVE‑2026‑2833/2835/2836) have been fixed, addressing request smuggling and cache poisoning issues; no active exploitation or PoC details are reported.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert announces the existence of a CVE (HTTP Request Smuggling via Premature Upgrade) but offers no PoC, exploit code, patch, or evidence of live attacks.
Infoflowcloud@infoflowcloudDisclosure
A new HTTP request smuggling vulnerability (CWE-444) has been disclosed affecting Pingora’s HTTP/1.1 upgrade handling, but no PoC, exploit, or patch details are provided.
CVE@CVEnewDisclosure
An HTTP request smuggling vulnerability (CWE‑444) has been identified in Pingora's handling of HTTP/1.1 connection upgrades.
PulsePatch.io@pulsepatchioPatch
The advisory alerts users to CVE-2026-2833, a Premature Upgrade HTTP Request Smuggling vulnerability in pingora-core, and recommends upgrading to version 0.8.0 to mitigate risks such as cache poisoning and WAF bypass.