Misbar | مسبار[verified]@MisbarSecPatch
Cloudflare disclosed critical request smuggling CVEs in Pingora and released security updates; no active exploitation or PoC is mentioned.
ThreatSynop[verified]@ThreatSynopPatch
Cloudflare released Pingora 0.8.0 to patch CVE‑2026‑2833/2835/2836, addressing request smuggling, cache poisoning, and ACL bypass via desynchronization flaws.
ThreatSynop[verified]@ThreatSynopPatch
Cloudflare's blog announces that three Pingora OSS CVEs enabling request smuggling, cache poisoning, and cross‑user hijacking have been patched in version 0.8.0, urging users to upgrade.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
An alert is issued for CVE‑2026‑2836, a cache‑poisoning vulnerability that arises from insecure default cache keys. No PoC, exploit code, or patch information is provided.
DailyCVE@dailycveDisclosure
The text announces the discovery of a cache poisoning vulnerability in Pingora (CVE-2026-2836) with a high severity rating, but provides no further technical, exploit, or remediation details.
Infoflowcloud@infoflowcloudDisclosure
The tweet discloses a cache‑poisoning vulnerability (CVE‑2026‑2836) in Pingora’s default cache key construction, providing technical details but no PoC, exploit, or patch information.
CVE@CVEnewDisclosure
The text announces the discovery of a cache‑poisoning vulnerability in Pingora’s default cache key logic, with no evidence of a PoC, exploit, or active exploitation noted.