Today we’re disclosing request smuggling vulnerabilities when our open source Pingora service is deployed as an ingress proxy and how we’ve fixed them in Pingora 0.8.0.
AI Summary
Cloudflare's Pingora open source framework had three request smuggling vulnerabilities (CVE-2026-2833, CVE-2026-2835, and CVE-2026-2836) that could be exploited by attackers. The vulnerabilities allowed bypassing proxy-layer security controls and enabled desync attacks for cross-user hijacking, credential theft, and poisoning proxy-layer caches. Cloudflare's engineering team patched the issues in Pingora 0.8.0 and recommends users to upgrade as soon as possible. The vulnerabilities were not exploitable in Cloudflare's CDN due to its architecture, but they affected standalone Pingora deployments exposed to the internet.