Sploitus

CVE-2025-4366

No indexed exploits for CVE-2025-4366 yet

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. Fixed in:  https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff https://github.com/cloudflare/pingora/commit/fda3317ec822678564d641e7cf1c9b77ee3759ff Impact: The issue could lead to request smuggling in cases where Pingora’s proxying framework, pingora-proxy, is used for caching allowing an attacker to manipulate headers and URLs in subsequent requests made on the same HTTP/1.1 connection.

Affected products
Pingora
Cloudflare Pingora
< 0.5.0
Fix
Available
CVSS 4.0
7.4 HIGH
CVSS 3.1
6.1 MEDIUM
EPSS
0.4% (35th percentile)
Weakness
CWE-444
NVD status
Analyzed
Published
2025-05-22
CVE-2025-4366 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-4366 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-4366 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.