Executive brief
Progress MarkLogic Server is a NoSQL database platform used for content management and search applications. An HTTP request smuggling vulnerability in its HTTP App Server allows attackers to bypass security controls and hijack user sessions by exploiting how the server interprets malformed HTTP requests. This could enable unauthorized data access, credential theft, or complete compromise of authenticated user accounts.
Technical details
The vulnerability is an HTTP request smuggling flaw that occurs when a specially crafted HTTP request contains both Content-Length and Transfer-Encoding headers, causing a reverse proxy and MarkLogic Server to interpret request boundaries differently. This desynchronization allows an attacker to inject malicious requests that bypass authentication and authorization checks. The attack is network-accessible and requires no user interaction or prior authentication. Successful exploitation enables session hijacking, credential capture, and complete authentication bypass. Patches are available for versions 11.3.6 and 12.0.3.
Affected products
- Progress MarkLogic Server before 11.3.6 and 12.0.3
Timeline
- 2026-08-05: disclosed