Fixed in: https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff
Impact: The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16165 | Pingora has a Request Smuggling Vulnerability |
Github GHSA |
GHSA-93c7-7xqw-w357 | Pingora has a Request Smuggling Vulnerability |
| Link | Providers |
|---|---|
| https://github.com/cloudflare/pingora |
|
Wed, 06 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloudflare
Cloudflare pingora |
|
| CPEs | cpe:2.3:a:cloudflare:pingora:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cloudflare
Cloudflare pingora |
|
| Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 22 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 22 May 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. Fixed in: https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff Impact: The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection. | |
| Title | Request Smuggling Vulnerability in Pingora | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2025-06-18T13:46:25.042Z
Reserved: 2025-05-05T17:42:10.923Z
Link: CVE-2025-4366
Updated: 2025-05-22T18:31:57.892Z
Status : Analyzed
Published: 2025-05-22T16:15:55.180
Modified: 2025-08-06T17:01:13.763
Link: CVE-2025-4366
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA