Product
cloudflare pingora
4 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2836
CVE-2026-2835
CVE-2026-2833
CVE-2025-4366
< 0.8.0
A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue o
< 0.8.0
An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests.
< 0.8.0
An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occur
< 0.5.0
A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests