CVE-2026-2835 is a critical HTTP Request Smuggling vulnerability (CWE-444) in Pingora, specifically affecting its parsing of HTTP/1.0 and Transfer-Encoding requests. This flaw allows attackers to desynchronize Pingora's request framing from backend servers, primarily impacting standalone Pingora deployments. With a CVSS score of 9.3 (CRITICAL), successful exploitation can bypass ACLs, poison caches, and enable cross-user attacks. There is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion. Users should upgrade to Pingora v0.8.0 or implement workarounds to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.0CPE matchmatch criteria | cpe:2.3:a:cloudflare:pingora:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.