CVE-2026-9190: HTTP request smuggling in Progress MarkLogic Server
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9190?
The severity of CVE-2026-9190 is critical, with a CVSS score of 9.1.
How do I fix CVE-2026-9190?
To fix CVE-2026-9190, upgrade Progress MarkLogic Server to version 11.3.6 or 12.0.3 or later.
What kind of attacks can be executed using CVE-2026-9190?
CVE-2026-9190 allows remote attackers to bypass authentication and authorization checks, hijack user sessions, and capture credentials.
Which versions of Progress MarkLogic Server are affected by CVE-2026-9190?
Progress MarkLogic Server versions before 11.3.6 and 12.0.3 are affected by CVE-2026-9190.
What is the nature of CVE-2026-9190 vulnerability?
CVE-2026-9190 is an HTTP request smuggling vulnerability found in the HTTP App Server of Progress MarkLogic Server.