CVE-2023-40225
HIGHHAProxy < 2.0.32, 2.1.x-2.2.30, 2.3.x-2.4.23, 2.5.x-2.6.14, 2.7.x-2.7.9, 2.8.x-2.8.1 - HTTP Request Smuggling
Title source: llmDescription
HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.
References (6)
Core 6
Core References
Technical Description
https://cwe.mitre.org/data/definitions/436.html
Exploit, Issue Tracking, Vendor Advisory
https://github.com/haproxy/haproxy/issues/2237
Release Notes
https://www.haproxy.org/download/2.6/src/CHANGELOG
Release Notes
https://www.haproxy.org/download/2.7/src/CHANGELOG
Release Notes
https://www.haproxy.org/download/2.8/src/CHANGELOG
Scores
CVSS v3
7.2
EPSS
0.0181
EPSS Percentile
75.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-444
Status
published
Products (1)
haproxy/haproxy
< 2.0.32
Published
Aug 10, 2023
Tracked Since
Feb 18, 2026