CVE-2021-40346
08.09.2021, 17:15
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.Enginsight
Vendor | Product | Version |
---|---|---|
haproxy | haproxy | 2.0.0 ≤ 𝑥 < 2.0.25 |
haproxy | haproxy | 2.2.0 ≤ 𝑥 < 2.2.17 |
haproxy | haproxy | 2.3.0 ≤ 𝑥 < 2.3.14 |
haproxy | haproxy | 2.4.0 ≤ 𝑥 < 2.4.4 |
haproxy | haproxy | 2.5:dev0 |
haproxy | haproxy | 2.5:dev1 |
haproxy | haproxy | 2.5:dev2 |
haproxy | haproxy | 2.5:dev3 |
haproxy | haproxy | 2.5:dev4 |
haproxy | haproxy | 2.5:dev5 |
haproxy | haproxy | 2.5:dev6 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References