CVE-2026-2836 | Cloudflare pingora up to 0.7.x Cache cross-domain policy
A vulnerability was found in Cloudflare pingora up to 0.7.x. It has been declared as critical. Affected by this issue is some unknown functionality of the component Cache Handler. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.
The identification of this vulnerability is CVE-2026-2836. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.