CVE-2019-18277
A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).
- Haproxy
- < 2.0.6
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 10.0% (95th percentile)
- Weakness
- CWE-444
- NVD status
- Modified
- Published
- 2019-10-23
No indexed exploits for CVE-2019-18277 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-18277 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.