CVE-2026-9190

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-05 16:17

Updated : 2026-09-03 14:49


NVD link : CVE-2026-9190

Mitre link : CVE-2026-9190

CVE.ORG link : CVE-2026-9190


JSON object : View

Products Affected

progress

  • marklogic_server
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')