An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
2021-09-08T17:15:12.457
2024-11-21T06:23:54.997
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | haproxy | haproxy | < 2.0.25 | Yes |
| Application | haproxy | haproxy | < 2.2.17 | Yes |
| Application | haproxy | haproxy | < 2.3.14 | Yes |
| Application | haproxy | haproxy | < 2.4.4 | Yes |
| Application | haproxy | haproxy | 2.5 | Yes |
| Application | haproxy | haproxy | 2.5 | Yes |
| Application | haproxy | haproxy | 2.5 | Yes |
| Application | haproxy | haproxy | 2.5 | Yes |
| Application | haproxy | haproxy | 2.5 | Yes |
| Application | haproxy | haproxy | 2.5 | Yes |
| Application | haproxy | haproxy | 2.5 | Yes |
| Operating System | debian | debian_linux | 11.0 | Yes |
| Operating System | fedoraproject | fedora | 33 | Yes |
| Operating System | fedoraproject | fedora | 34 | Yes |