Misbar | مسبار[verified]@MisbarSecPatch
Cloudflare confirmed three critical request‑smuggling CVEs in their Pingora framework, described how the vulnerabilities could be exploited, and released patches to mitigate the risks.
ThreatSynop[verified]@ThreatSynopPatch
Cloudflare has released a patch for three critical Pingora vulnerabilities that allow request smuggling and cache poisoning; the focus is on the availability and application of this fix.
ThreatSynop[verified]@ThreatSynopPatch
Cloudflare publicly disclosed and patched three Pingora OSS vulnerabilities (CVE-2026-2833, CVE-2026-2835, CVE-2026-2836), fixing them in version 0.8.0 and highlighting potential risks to self‑managed deployments.
Gray Hats@the_yellow_fallPatch
Three critical request smuggling and cache poisoning flaws—including CVE-2026-2835—in Cloudflare’s Pingora Rust framework have been identified, and users are urged to update immediately.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisClosure
The alert announces CVE-2026-2835, a request‑smuggling flaw involving HTTP/1.0 and Transfer‑Encoding parsing, and links to an intel report but does not provide PoC, exploit tools, or patch information.
Infoflowcloud@infoflowcloudDisclosure
A newly discovered HTTP Request Smuggling vulnerability (CVE‑2026‑2835) affecting Pingora’s HTTP/1.0 and Transfer‑Encoding parsing has been disclosed, providing technical details but no PoC, exploit, active usage, or patch.
CVE@CVEnewDisclosure
Pingora is vulnerable to HTTP Request Smuggling (CWE-444) as highlighted by CVE-2026-2835.
PulsePatch.io@pulsepatchioPatch
The text reports a critical HTTP Request Smuggling vulnerability in pingora-core (CVE-2026-2835) and recommends updating to version 0.8.0, providing technical details but no PoC or exploit code.