pingora is vulnerable to Resource Exhaustion
75
High Risk
Cloudflare Pingora HTTP/2 handling is reported to be vulnerable to an HPACK indexed-reference header bomb combined with response flow-control stalling. A client can send many cheap header references and keep the server from freeing per-request allocations. Affected servers can suffer remote memory exhaustion and availability loss through HTTP/2 traffic. No patched Pingora release was available in the checked evidence.
You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled.
pingora is vulnerable to Resource Exhaustion in versions 0.0.1 - 0.8.0.
Disable HTTP/2 or front Pingora with a proxy that enforces a hard cap on header count per request until a patched release is available.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant