Skip to content
CloudflareGHSA-93c7-7xqw-w357

Request Smuggling Vulnerability in Pingora

High7.4CVE-2025-4366 · Published Jun 20, 2025

This issue is already disclosed at https://www.cve.org/cverecord?id=CVE-2025-4366 A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. ### Fixed in https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff ### Impact The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection. ### Additional Information https://blog.cloudflare.com/resolving-a-request-smuggling-vulnerability-in-pingora/

GitHub advisory

Affected versions

PackageAffectedFixed in
pingora-core
crates.io
< 0.5.00.5.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-444

More Cloudflare advisories

All Cloudflare
Advisory
Infinite loop triggered by connection ID retirement
High8.7Aug 7, 2025
Cloudflare vite plugin exposes secrets over the built-in dev server
LowJul 7, 2025
Incorrect congestion window growth by invalid ACK ranges
High7.5Jun 17, 2025
Incorrect congestion window growth by optimistic ACK
Medium5.3Jun 17, 2025
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
LowJun 10, 2025
PKCE bypass via downgrade attack
Medium5.3May 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.