Sploitus

CVE-2019-18277

No indexed exploits for CVE-2019-18277 yet

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

Affected products
Alt Linux, Centos, Haproxy, Red Hat, Suse, Ubuntu
Haproxy
< 2.0.6
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
10.0% (95th percentile)
Weakness
CWE-444
NVD status
Modified
Published
2019-10-23
CVE-2019-18277 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-18277 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-18277 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.