HackerOne Disclosed Reports - 2026-09-13

0 Replies, 7 Views

Logo
High
resolved

HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers


Bug reported by Quan Le was disclosed at September 14, 2026, 4:57 am   |   HTTP Request Smuggling

A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)