Fixing request smuggling vulnerabilities in Pingora OSS deployments

TL;DR AI
2 min readKey summary
Cloudflare received reports of HTTP/1.x request smuggling vulnerabilities in Pingora reports received in December 2025.
Pingora released a patched version 0.8.0, pingora 0.8.0 includes fixes and hardening for the vulnerabilities.
Vulnerabilities were assigned CVE identifiers, cVE-2026-2833, CVE-2026-2835, and CVE-2026-2836.
Researcher reported the issues through a bug bounty program reporter identified as Rajat Raghav (xclow3n).
Cloudflare CDN was not affected by the vulnerabilities investigation found no impact to Cloudflare CDN or customer traffic.
