CVE-2021-40346

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
08/09/2021
Last modified:
07/11/2023

Description

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.25 (excluding)
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* 2.2.0 (including) 2.2.17 (excluding)
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* 2.3.0 (including) 2.3.14 (excluding)
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* 2.4.0 (including) 2.4.4 (excluding)
cpe:2.3:a:haproxy:haproxy:2.5:dev0:*:*:*:*:*:*
cpe:2.3:a:haproxy:haproxy:2.5:dev1:*:*:*:*:*:*
cpe:2.3:a:haproxy:haproxy:2.5:dev2:*:*:*:*:*:*
cpe:2.3:a:haproxy:haproxy:2.5:dev3:*:*:*:*:*:*
cpe:2.3:a:haproxy:haproxy:2.5:dev4:*:*:*:*:*:*
cpe:2.3:a:haproxy:haproxy:2.5:dev5:*:*:*:*:*:*
cpe:2.3:a:haproxy:haproxy:2.5:dev6:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*