CVE-2026-2836Disclosure(cloudflare / pingora)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cloudflare pingora systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache keys using only the URI path, excluding critical factors such as the host header (authority). Operators relying on the default are vulnerable to cache poisoning, and cross-origin responses may be improperly served to users. Impact This vulnerability affects users of Pingora's alpha proxy caching feature who relied on the default CacheKey implementation. An attacker could exploit this for: * Cross-tenant data leakage: In multi-tenant deployments, poison the cache so that users from one tenant receive cached responses from another tenant * Cache poisoning attacks: Serve malicious content to legitimate users by poisoning shared cache entries Cloudflare's CDN infrastructure was not affected by this vulnerability, as Cloudflare's default cache key implementation uses multiple factors to prevent cache key poisoning and never made use of the previously provided default. Mitigation: We strongly recommend Pingora users to upgrade to Pingora v0.8.0 or higher, which removes the insecure default cache key implementation. Users must now explicitly implement their own callback that includes appropriate factors such as Host header, origin server HTTP scheme, and other attributes their cache should vary on. Pingora users on previous versions may also remove any of their default CacheKey usage and implement their own that should at minimum include the host header / authority and upstream peer’s HTTP scheme.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pingora

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-09); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
pingora

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-09: 3Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 203-0503-0903-1003-12
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-093
Disclosure2Patch1
2026-03-102
Patch2
2026-03-121
Disclosure1
Full discourse7 posts
  • Misbar | مسبار@MisbarSec
    Patch

    تلقت Cloudflare بلاغات حول ثغرات حرجة لتهريب طلبات HTTP/1.x ضمن إطار عمل Pingora مفتوح المصدر عند استخدامه كوكيل دخول (ingress proxy). تتضمن هذه الثغرات، المصنفة تحت (CVE-2026-2836, CVE-2026-2835, CVE-2026-2833)، إمكانية استغلال تضارب في تفسير الطلبات بين الوكيل والخادم الخلفي، مما قد يؤدي إلى تجاوز آليات الأمان وتسميم الذاكرة المؤقتة. لقد قامت Cloudflare بمعالجة هذه الثغرات وإصدار تحديثات أمنية. 🔗 للمزيد: https://blog.cloudflare.com/pingora-oss-smuggling-vulnerabilities/

    Post summary

    Cloudflare disclosed critical request smuggling CVEs in Pingora and released security updates; no active exploitation or PoC is mentioned.

    0002058
    65 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cloudflare Patches Critical Pingora Flaws Enabling Request Smuggling and Cache Poisoning Cloudflare released Pingora 0.8.0 to fix three critical vulnerabilities—CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836—that could let attackers bypass proxy ACLs and WAFs, smuggle hidden requests, and poison caches in standalone internet-exposed deployments. The issue matters because desync flaws in reverse proxies can quietly undermine core security controls and expose downstream applications to session hijacking and cross-user impact. 🎯 Target: Global/Internet-Exposed Proxies #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/cloudflare-pingora-vulnerabilities/

    Post summary

    Cloudflare released Pingora 0.8.0 to patch CVE‑2026‑2833/2835/2836, addressing request smuggling, cache poisoning, and ACL bypass via desynchronization flaws.

    1000038
    280 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2836 - Cache poisoning via insecure-by-default cache key Intel Report: https://ift.tt/XdD3ac6

    Post summary

    An alert is issued for CVE‑2026‑2836, a cache‑poisoning vulnerability that arises from insecure default cache keys. No PoC, exploit code, or patch information is provided.

    0001037
    343 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Pingora, Cache Poisoning, #CVE-2026-2836 (HIGH) https://dailycve.com/pingora-cache-poisoning-cve-2026-2836-high/

    Post summary

    The text announces the discovery of a cache poisoning vulnerability in Pingora (CVE-2026-2836) with a high severity rating, but provides no further technical, exploit, or remediation details.

    0000023
    168 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2836 A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key… https://www.cve.org/CVERecord?id=CVE-2026-2836 ----- Traducción: CVE-2026-2836 Se … http://infoflow.cloud`

    Post summary

    The tweet discloses a cache‑poisoning vulnerability (CVE‑2026‑2836) in Pingora’s default cache key construction, providing technical details but no PoC, exploit, or patch information.

    0000031
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2836 A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key… https://www.cve.org/CVERecord?id=CVE-2026-2836

    Post summary

    The text announces the discovery of a cache‑poisoning vulnerability in Pingora’s default cache key logic, with no evidence of a PoC, exploit, or active exploitation noted.

    00000183
    56.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cloudflare patches Pingora request smuggling flaws that could bypass proxy defenses Cloudflare disclosed three Pingora OSS vulnerabilities—CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836—that can enable request smuggling, cache poisoning, and cross-user hijacking in Internet-exposed ingress proxy deployments, and fixed them in Pingora 0.8.0. This matters because vulnerable self-managed Pingora setups could let attackers slip past proxy-layer controls and desynchronize backend traffic even though Cloudflare’s own CDN was not affected. 🎯 Target: Global/Organizations Using Pingora OSS as an Ingress Proxy #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://blog.cloudflare.com/pingora-oss-smuggling-vulnerabilities/

    Post summary

    Cloudflare's blog announces that three Pingora OSS CVEs enabling request smuggling, cache poisoning, and cross‑user hijacking have been patched in version 0.8.0, urging users to upgrade.

    0000080
    273 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudflarepingora---

Explore more