Description
A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning.

Fixed in:  https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff

Impact: The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection.
Published: 2025-05-22
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-16165 Pingora has a Request Smuggling Vulnerability
Github GHSA Github GHSA GHSA-93c7-7xqw-w357 Pingora has a Request Smuggling Vulnerability
References
History

Wed, 06 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Cloudflare
Cloudflare pingora
CPEs cpe:2.3:a:cloudflare:pingora:*:*:*:*:*:*:*:*
Vendors & Products Cloudflare
Cloudflare pingora
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.001}

epss

{'score': 0.00076}


Wed, 18 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Thu, 22 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 May 2025 16:00:00 +0000

Type Values Removed Values Added
Description A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. Fixed in:  https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff Impact: The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection.
Title Request Smuggling Vulnerability in Pingora
Weaknesses CWE-444
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Cloudflare Pingora
cve-icon MITRE

Status: PUBLISHED

Assigner: cloudflare

Published:

Updated: 2025-06-18T13:46:25.042Z

Reserved: 2025-05-05T17:42:10.923Z

Link: CVE-2025-4366

cve-icon Vulnrichment

Updated: 2025-05-22T18:31:57.892Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-22T16:15:55.180

Modified: 2025-08-06T17:01:13.763

Link: CVE-2025-4366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses