GHSA-93c7-7xqw-w357

Suggest an improvement
Source
https://github.com/advisories/GHSA-93c7-7xqw-w357
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-93c7-7xqw-w357/GHSA-93c7-7xqw-w357.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-93c7-7xqw-w357
Aliases
Published
2025-06-20T18:07:47Z
Modified
2025-06-20T18:42:06.854880Z
Severity
  • 7.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Pingora has a Request Smuggling Vulnerability
Details

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning.

Fixed in

https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff

Impact

The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-444"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-06-20T18:07:47Z"
}
References

Affected packages

crates.io / pingora-core

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0