CVE-2026-2836 — A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache — CVE Database · The Intelligence Room