Request Smuggling Vulnerability in Pingora
High7.4CVE-2025-4366 · Published Jun 20, 2025
This issue is already disclosed at https://www.cve.org/cverecord?id=CVE-2025-4366 A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. ### Fixed in https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff ### Impact The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection. ### Additional Information https://blog.cloudflare.com/resolving-a-request-smuggling-vulnerability-in-pingora/
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pingora-core crates.io | < 0.5.0 | 0.5.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-444
More Cloudflare advisories
All Cloudflare| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 72025 | Infinite loop triggered by connection ID retirement | High8.7 | 0.24.5 |
| Jul 72025 | Cloudflare vite plugin exposes secrets over the built-in dev server | Low | 1.6.0 |
| Jun 172025 | Incorrect congestion window growth by invalid ACK ranges | High7.5 | 0.24.4 |
| Jun 172025 | Incorrect congestion window growth by optimistic ACK | Medium5.3 | 0.24.4 |
| Jun 102025 | CIRCL-Fourq: Missing and wrong validation can lead to incorrect results | Low | 1.6.1 |
| May 12025 | PKCE bypass via downgrade attack | Medium5.3 | 0.0.5 |