cbcvebase.
CVE-2022-0711
published 2022-03-02

CVE-2022-0711: A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP…

PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
16.56%
96.6th percentile
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianhaproxy< haproxy 2.4.13-1 (bookworm)haproxy 2.4.13-1 (bookworm)
haproxyhaproxy
haproxyhaproxy>= 0 < 2.2.9-2+deb11u32.2.9-2+deb11u3
haproxyhaproxy>= 0 < 2.4.13-12.4.13-1
haproxyhaproxy>= 0 < 2.4.13-12.4.13-1
haproxyhaproxy>= 0 < 2.4.13-12.4.13-1
haproxyhaproxy>= 2.2.0 < 2.2.212.2.21
haproxyhaproxy>= 2.3.0 < 2.3.182.3.18
haproxyhaproxy>= 2.4.0 < 2.4.132.4.13
msrccbl2_haproxy_2.4.13-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
redhatopenshift_container_platform

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: HAProxy enters an infinite loop when processing HTTP responses containing the 'Set-Cookie2' header — monitor for HAProxy process CPU spikes or unresponsiveness correlated with backend responses carrying this header.
  • Vulnerability is only present in HAProxy versions 1.9 and later (Native HTTP Representation / HTX support required); versions shipped with RHEL 6/7/8 and Red Hat Software Collections are NOT affected — scope detection to HTX-enabled deployments.
  • Detection focus: inspect HTTP response traffic flowing through HAProxy for the presence of the 'Set-Cookie2' header, which is the crafted packet vector for this DoS.
  • ·Only HAProxy deployments using the Native HTTP Representation (HTX), introduced in version 1.9, are vulnerable. Older versions without HTX support are not affected.
  • ·The attack vector is a crafted HTTP *response* packet (from a backend server), not a client request — detection/filtering should be applied on backend-to-HAProxy traffic, not just client-to-HAProxy.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.