CVE-2021-40346
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
- Haproxy
- < 2.0.25, 2.2.17, 2.3.14, 2.4.4, 2.5
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 57.9% (99th percentile)
- Weakness
- CWE-190
- NVD status
- Modified
- Published
- 2021-09-08
CVE-2021-40346 at NVD
5 known exploits for CVE-2021-40346
Proof-of-concept code and exploit modules indexed by Sploitus