pingora-core
crates.io4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pingora-corepage 1 of 1
- CVE-2025-4366MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.5.02025-05-22
A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and po…
- CVE-2025-8671HIGHCVSS 7.5EG 7.5✓ Fixed in 0.6.02025-08-13
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (D…
- CVE-2026-2833CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.8.02026-03-05
An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, causing the proxy to pass through the re…
- CVE-2026-2835CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.8.02026-03-05
An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handl…
Check whether pingora-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pingora-core CVEs against the assets you own.
Start Free Scan →