Detects Cloudflare Pingora reverse proxies at version 0.7.0 or earlier, where the HTTP/1.1 parser prematurely switches to pass-through mode on requests with an Upgrade header — before the backend confirms with 101 Switching Protocols. An attacker can smuggle arbitrary HTTP requests that bypass all proxy-level security controls (WAF, ACL, rate limiting).
Is your app exploitable through CVE-2026-2833?
Scan your domain free