pingora-core is vulnerable to HTTP Request/Response Smuggling
93
Critical Risk
Affected versions of this package are vulnerable to HTTP request smuggling. When handling HTTP/1.1 requests containing an Upgrade header, the proxy may forward remaining connection bytes to the backend before the backend has accepted the upgrade. An attacker can exploit this behavior to append a malicious payload after the initial request, which the backend may interpret as a subsequent request. This may allow attackers to bypass proxy-level security controls, poison upstream connections or caches, and potentially perform cross-user session hijacking.
You are affected if you are using a version that falls within the vulnerable range.
pingora-core is vulnerable to HTTP Request/Response Smuggling in versions 0.1.0 - 0.7.0.
Upgrade the pingora-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant