CVE-2026-2835Patch(cloudflare / pingora)

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch cloudflare pingora systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding values, allowing attackers to send HTTP/1.0 requests in a way that would desync Pingora’s request framing from backend servers’. Impact This vulnerability primarily affects standalone Pingora deployments in front of certain backends that accept HTTP/1.0 requests. An attacker could craft a malicious payload following this request that Pingora forwards to the backend in order to: * Bypass proxy-level ACL controls and WAF logic * Poison caches and upstream connections, causing subsequent requests from legitimate users to receive responses intended for smuggled requests * Perform cross-user attacks by hijacking sessions or smuggling requests that appear to originate from the trusted proxy IP Cloudflare's CDN infrastructure was not affected by this vulnerability, as its ingress proxy layers forwarded HTTP/1.1 requests only, rejected ambiguous framing such as invalid Content-Length values, and forwarded a single Transfer-Encoding: chunked header for chunked requests. Mitigation: Pingora users should upgrade to Pingora v0.8.0 or higher that fixes this issue by correctly parsing message length headers per RFC 9112 and strictly adhering to more RFC guidelines, including that HTTP request bodies are never close-delimited. As a workaround, users can reject certain requests with an error in the request filter logic in order to stop processing bytes on the connection and disable downstream connection reuse. The user should reject any non-HTTP/1.1 request, or a request that has invalid Content-Length, multiple Transfer-Encoding headers, or Transfer-Encoding header that is not an exact “chunked” string match.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pingora

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-06); latest day: 3
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
pingora

Deep dive

Activity timeline10 mentions / 4d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-06: 3Mentions · 2026-03-09: 3Mentions · 2026-03-10: 3Patch / Workaround · 2026-03-06: 3Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 3Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 303-0503-0603-0903-10
Signal classification3 categories
Patch
770.0%
Disclosure
220.0%
DisClosure
110.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-051
DisClosure1
2026-03-063
Patch3
2026-03-093
Disclosure2Patch1
2026-03-103
Patch3
Full discourse10 posts
  • Gray Hats@the_yellow_fall
    Patch

    Discover three critical flaws (including CVE-2026-2835) in Cloudflare's Pingora Rust framework causing request smuggling and cache poisoning. Update now. #Pingora #Cloudflare #CVE #CyberSecurity #RequestSmuggling #InfoSec #Vulnerability #PatchAlert https://securityonline.info/critical-request-smuggling-cache-flaws-discovered-in-cloudflares-pingora/ https://t.co/bv1UggubEq

    Post summary

    Three critical request smuggling and cache poisoning flaws—including CVE-2026-2835—in Cloudflare’s Pingora Rust framework have been identified, and users are urged to update immediately.

    03030343
    10.6K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    تلقت Cloudflare بلاغات حول ثغرات حرجة لتهريب طلبات HTTP/1.x ضمن إطار عمل Pingora مفتوح المصدر عند استخدامه كوكيل دخول (ingress proxy). تتضمن هذه الثغرات، المصنفة تحت (CVE-2026-2836, CVE-2026-2835, CVE-2026-2833)، إمكانية استغلال تضارب في تفسير الطلبات بين الوكيل والخادم الخلفي، مما قد يؤدي إلى تجاوز آليات الأمان وتسميم الذاكرة المؤقتة. لقد قامت Cloudflare بمعالجة هذه الثغرات وإصدار تحديثات أمنية. 🔗 للمزيد: https://blog.cloudflare.com/pingora-oss-smuggling-vulnerabilities/

    Post summary

    Cloudflare confirmed three critical request‑smuggling CVEs in their Pingora framework, described how the vulnerabilities could be exploited, and released patches to mitigate the risks.

    0002058
    65 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cloudflare Patches Critical Pingora Flaws Enabling Request Smuggling and Cache Poisoning Cloudflare released Pingora 0.8.0 to fix three critical vulnerabilities—CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836—that could let attackers bypass proxy ACLs and WAFs, smuggle hidden requests, and poison caches in standalone internet-exposed deployments. The issue matters because desync flaws in reverse proxies can quietly undermine core security controls and expose downstream applications to session hijacking and cross-user impact. 🎯 Target: Global/Internet-Exposed Proxies #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/cloudflare-pingora-vulnerabilities/

    Post summary

    Cloudflare has released a patch for three critical Pingora vulnerabilities that allow request smuggling and cache poisoning; the focus is on the availability and application of this fix.

    1000038
    280 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    DisClosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2835 - HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing Intel Report: https://ift.tt/GUqyBCb

    Post summary

    The alert announces CVE-2026-2835, a request‑smuggling flaw involving HTTP/1.0 and Transfer‑Encoding parsing, and links to an intel report but does not provide PoC, exploit tools, or patch information.

    0001040
    343 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2835 An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly all… https://www.cve.org/CVERecord?id=CVE-2026-2835 ----- Traducción: CVE-2026-2835 Una… http://infoflow.cloud`

    Post summary

    A newly discovered HTTP Request Smuggling vulnerability (CVE‑2026‑2835) affecting Pingora’s HTTP/1.0 and Transfer‑Encoding parsing has been disclosed, providing technical details but no PoC, exploit, active usage, or patch.

    0000031
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2835 An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly all… https://www.cve.org/CVERecord?id=CVE-2026-2835

    Post summary

    Pingora is vulnerable to HTTP Request Smuggling (CWE-444) as highlighted by CVE-2026-2835.

    00000209
    56.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cloudflare patches Pingora request smuggling flaws that could bypass proxy defenses Cloudflare disclosed three Pingora OSS vulnerabilities—CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836—that can enable request smuggling, cache poisoning, and cross-user hijacking in Internet-exposed ingress proxy deployments, and fixed them in Pingora 0.8.0. This matters because vulnerable self-managed Pingora setups could let attackers slip past proxy-layer controls and desynchronize backend traffic even though Cloudflare’s own CDN was not affected. 🎯 Target: Global/Organizations Using Pingora OSS as an Ingress Proxy #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://blog.cloudflare.com/pingora-oss-smuggling-vulnerabilities/

    Post summary

    Cloudflare publicly disclosed and patched three Pingora OSS vulnerabilities (CVE-2026-2833, CVE-2026-2835, CVE-2026-2836), fixing them in version 0.8.0 and highlighting potential risks to self‑managed deployments.

    0000080
    273 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical HTTP Request Smuggling flaw (CVE-2026-2835) affects `pingora-core`. This vulnerability, related to HTTP/1.0 and Transfer-Encoding misparsing, could allow security control bypass. Update to version 0.8.0. #Pingora #Infosec #HTTP https://www.pulsepatch.io/posts/cve-2026-2835-pingora-http-request-smuggling

    Post summary

    The text reports a critical HTTP Request Smuggling vulnerability in pingora-core (CVE-2026-2835) and recommends updating to version 0.8.0, providing technical details but no PoC or exploit code.

    0000037
    1 followersView on X
  • Vulert@vulert_official
    Patch

    🚨🚨 CVE-2026-2835 impacts Pingora < 0.8.0 due to improper HTTP request handling, creating a serious security risk. Upgrade to 0.8.0+ immediately to reduce exploitation risk. 🔍 https://vulert.com/vuln-db/CVE-2026-2835 #CyberSecurity #AppSec #Vulert https://t.co/HON0OFr2GX

    Post summary

    The tweet highlights a serious vulnerability in Pingora versions below 0.8.0 due to improper HTTP request handling and urges users to upgrade to v0.8.0+.

    0000058
    124 followersView on X
  • Vulert@vulert_official
    Patch

    🚨🚨 CVE-2026-2835 impacts Pingora < 0.8.0 due to improper HTTP request handling, creating a serious security risk. Upgrade to 0.8.0+ immediately to reduce exploitation risk. 🔍 https://vulert.com/vuln-db/CVE-2026-2835 #CyberSecurity #AppSec #Vulert https://t.co/VfKUtYSINq

    Post summary

    CVE‑2026‑2835 causes improper HTTP request handling in Pingora versions prior to 0.8.0, posing a serious security risk; upgrading to 0.8.0 or later is recommended to mitigate the threat.

    0000052
    124 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudflarepingora---

Explore more