Back

CRITICAL

HTTP request smuggling in Progress MarkLogic Server

Published Aug 5, 2026

Description

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.

Affected products

Remediation

Vendor solution

Do not expose MarkLogic HTTP App Servers directly to untrusted networks. Configure a reverse proxy or web application firewall to reject requests that contain both Content-Length and Transfer-Encoding headers, and restrict access to trusted networks until the update can be applied.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Aug 5, 2026
Updated Aug 7, 2026
Reserved May 21, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Sep 3, 2026
Red Hat
Severity n/a
Public date n/a