Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-9190: Progress MarkLogic Server HTTP Request Smuggling Allows Session Hijacking
CVE-2026-9190
CVE-2026-9190
Summary
The Progress MarkLogic Server before 11.3.6 and 12.0.3 may allow an attacker to bypass security checks and steal user credentials. This can happen if a malicious person sends a specially crafted request to the server. To protect your server, update to version 11.3.6 or 12.0.3 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| progress software corporation | marklogic server | < 11.3.6 |
Original title
HTTP request smuggling in Progress MarkLogic Server
Original description
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.
nvd CVSS3.1
9.1
Vulnerability type
CWE-444
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026