CVE-2024-53008
MEDIUMHAProxy 2.6 < 2.6.18, 2.8 < 2.8.10, 2.9 < 2.9.9, 3.0 < 3.0.2 - HTTP Request Smuggling
Title source: llmDescription
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
References (6)
Core 6
Core References
Various Sources
https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=1afca10150ac3e4e2224055cc31b6f1e4a70efe2
Various Sources
https://git.haproxy.org/?p=haproxy-2.8.git;a=commit;h=01c1056a44823c5ffb8f74660b32c099d9b5355b
Various Sources
https://git.haproxy.org/?p=haproxy-2.9.git;a=commit;h=4bcaece344c8738dac1ab5bd8cc81e2a22701d71
Various Sources
https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=95a607c4b3af09be2a495b9c2872ea252ccff603
Various Sources
https://www.haproxy.org/
Third Party Advisory
https://jvn.jp/en/jp/JVN88385716/
Scores
CVSS v3
5.3
EPSS
0.0102
EPSS Percentile
58.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-444
Status
published
Products (4)
HAProxy Project/HAProxy 2.6
2.6.18 and earlier
HAProxy Project/HAProxy 2.8
2.8.10 and earlier
HAProxy Project/HAProxy 2.9
2.9.9 and earlier
HAProxy Project/HAProxy 3.0
3.0.2 and earlier
Published
Nov 28, 2024
Tracked Since
Feb 18, 2026