top of page
perceptive_background_267k.jpg

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authenti…

Published:

5 augustus 2026 om 00:00:00

Alert date:

5 augustus 2026 om 19:04:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Identity & Access, Database & Storage

CVE-2026-9190 describes a critical HTTP request smuggling vulnerability in the HTTP App Server component of Progress MarkLogic Server. Affected versions include all releases prior to 11.3.6 and 12.0.3. The vulnerability is triggered by crafted HTTP requests containing both Content-Length and Transfer-Encoding headers, causing desynchronization between a reverse proxy and MarkLogic Server in interpreting request boundaries. A remote unauthenticated attacker can exploit this to bypass authentication and authorization controls, hijack legitimate user sessions, or capture user credentials. The vulnerability poses a significant risk to organizations using MarkLogic as a backend data platform behind a reverse proxy. Progress has issued a critical security alert and patches are available in versions 11.3.6 and 12.0.3. Organizations are advised to upgrade immediately to mitigate exposure.

Technical details

Mitigation steps:

Affected products:

Progress MarkLogic Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page