High
resolved
resolved
HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers
Bug reported by Quan Le was disclosed at September 14, 2026, 4:57 am | HTTP Request Smuggling
A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.

