CVE-2021-39242
HIGHHaproxy < 2.2.16 - Improper Exception Handling
Title source: ruleDescription
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
References (5)
Scores
CVSS v3
7.5
EPSS
0.0047
EPSS Percentile
64.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-755
Status
published
Affected Products (4)
haproxy/haproxy
< 2.2.16
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
Timeline
Published
Aug 17, 2021
Tracked Since
Feb 18, 2026