CVE-2026-9190: An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authoriza
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9190
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9190 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for An HTTP request
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-71277: rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks wheth…nvd · 2026-08-05
- mediumCVE-2026-71275: OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query paramet…nvd · 2026-08-05
- highCVE-2026-59675: When API audit logging is enabled, the middleware reads the entire HTTP request body into memo…nvd · 2026-08-05
- unknownCVE-2026-15314: Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the ha…nvd · 2026-08-04
- lowCVE-2026-58044: A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwardi…nvd · 2026-08-04
- highCVE-2026-69246: Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport t…nvd · 2026-08-03
More from NVD Recent CVEs
- highCVE-2026-9203: A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0…2026-08-05
- criticalCVE-2026-9195: A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 1…2026-08-05
- criticalCVE-2026-9193: An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic …2026-08-05
- criticalCVE-2026-9192: An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server befo…2026-08-05
- criticalCVE-2026-8709: An improper privilege management vulnerability in the REST API document patch operation of Prog…2026-08-05