An integer overflow exists in HAProxy 2.0 through 2.5 in htxaddheader that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.13-2ubuntu0.3", "binary_name": "haproxy" }, { "binary_version": "2.0.13-2ubuntu0.3", "binary_name": "haproxy-dbgsym" }, { "binary_version": "2.0.13-2ubuntu0.3", "binary_name": "haproxy-doc" }, { "binary_version": "2.0.13-2ubuntu0.3", "binary_name": "vim-haproxy" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.2.9-2ubuntu2", "binary_name": "haproxy" }, { "binary_version": "2.2.9-2ubuntu2", "binary_name": "haproxy-dbgsym" }, { "binary_version": "2.2.9-2ubuntu2", "binary_name": "haproxy-doc" }, { "binary_version": "2.2.9-2ubuntu2", "binary_name": "vim-haproxy" } ] }