Dark C0d3rs
HackerOne Disclosed Reports - 2026-09-13 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2026-09-13 (/Thread-HackerOne-Disclosed-Reports-2026-09-13)



HackerOne disclosed reports - 2026-09-13 - hashXploiter - 09-14-2026

Logo
High
resolved

HTTP Request Smuggling via Unsanitized Hop-by-Hop Headers


Bug reported by Quan Le was disclosed at September 14, 2026, 4:57 am   |   HTTP Request Smuggling

A vulnerability was found in Pingora that could allow HTTP request smuggling through improper handling of hop-by-hop headers. The issue was fixed in Pingora 0.9.0.