CVE-2023-25725
published 2023-02-14CVE-2023-25725: HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP…
PriorityP356critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
5.49%
91.9th percentile
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | haproxy | < haproxy 2.6.8-2 (bookworm) | haproxy 2.6.8-2 (bookworm) |
| haproxy | haproxy | < 2.0.31 | 2.0.31 |
| haproxy | haproxy | >= 0 < 2.2.9-2+deb11u4 | 2.2.9-2+deb11u4 |
| haproxy | haproxy | >= 0 < 2.6.8-2 | 2.6.8-2 |
| haproxy | haproxy | >= 0 < 2.6.8-2 | 2.6.8-2 |
| haproxy | haproxy | >= 0 < 2.6.8-2 | 2.6.8-2 |
| haproxy | haproxy | >= 2.1.0 < 2.2.29 | 2.2.29 |
| haproxy | haproxy | >= 2.3.0 < 2.4.22 | 2.4.22 |
| haproxy | haproxy | >= 2.5.0 < 2.5.12 | 2.5.12 |
| haproxy | haproxy | >= 2.6.0 < 2.6.9 | 2.6.9 |
| haproxy | haproxy | >= 2.7.0 < 2.7.3 | 2.7.3 |
| msrc | cbl2_haproxy_2.4.22-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_haproxy_2.1.5-2_on_cbl_mariner_1.0 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests with empty header field names sent to HAProxy, which can be used to truncate the HTTP header list and smuggle headers past access controls ↗
- →Monitor for HTTP request smuggling attempts targeting HAProxy that cause critical headers (Connection, Content-length, Transfer-Encoding, Host) to be dropped mid-processing ↗
- →Focus smuggling detection on HTTP/1.0 and HTTP/1.1 traffic to HAProxy; HTTP/2 and HTTP/3 are lower risk as headers disappear before parsing rather than after ↗
- ·HAProxy versions before 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31 are vulnerable; verify deployed version is patched to one of these fixed releases ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
HAProxy vulnerability
vendor_ubuntu·2024-12-03
CVE-2023-25725 HAProxy vulnerability
Title: HAProxy vulnerability
Summary: HAProxy could allow unintended access to network services.
Bahruz Jabiyev, Anthony Gavazzi, Engin Kirda, Kaan Onarlioglu, Adi Peleg,
and Harvey Tuch discovered that HAProxy incorrectly handled empty header
names. A remote attacker could possibly use this issue to manipulate
headers and bypass certain authentication checks and restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
haproxy: request smuggling attack in HTTP/1 header parsing
vendor_redhat·2023-02-14·CVSS 9.1
CVE-2023-25725 [CRITICAL] CWE-444 haproxy: request smuggling attack in HTTP/1 header parsing
haproxy: request smuggling attack in HTTP/1 header parsing
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
A flaw was found in HAProxy's headers processing that causes HAProxy to drop important headers fields such as Connection, Content-length,
Microsoft
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations aka "request smuggling." The HTTP header parsers in HAProxy may accept empty
vendor_msrc·2023-02-14·CVSS 9.1
CVE-2023-25725 [CRITICAL] HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations aka "request smuggling." The HTTP header parsers in HAProxy may accept empty
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3 the impact is limited because the headers disappear before being parsed and processed as if they had not been sent by the client. The fixed versions are 2.7.3 2.6.9 2.5.12 2.4.22 2.2.29 and 2.0.31.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use
Debian
CVE-2023-25725: haproxy - HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers...
vendor_debian·2023·CVSS 9.1
CVE-2023-25725 [CRITICAL] CVE-2023-25725: haproxy - HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers...
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
Scope: local
bookworm: resolved (fixed in 2.6.8-2)
bullseye: resolved (fixed in 2.2.9-2+deb11u4)
forky: resolved (fixed in 2.6.8-2)
sid: resolved (fixed in 2.6.8-2)
trixie: resolved (fixed in 2.6.8-
GHSA
GHSA-h2p2-w857-329f: HAProxy before 2
ghsa_unreviewed·2023-02-14
CVE-2023-25725 [CRITICAL] CWE-444 GHSA-h2p2-w857-329f: HAProxy before 2
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
OSV
CVE-2023-25725: HAProxy before 2
osv·2023-02-14·CVSS 9.1
CVE-2023-25725 [CRITICAL] CVE-2023-25725: HAProxy before 2
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
No detection rules found.
No public exploits indexed.
https://git.haproxy.org/?p=haproxy-2.7.git%3Ba=commit%3Bh=a0e561ad7f29ed50c473f5a9da664267b60d1112https://lists.debian.org/debian-lts-announce/2023/02/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPTJQHKUEU2PQ7RWFUYAFLAD4STEIKHU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JM5NCIBTHYDTLPY2UNC4HO2VAHHE6CJG/https://www.debian.org/security/2023/dsa-5348https://www.haproxy.org/https://git.haproxy.org/?p=haproxy-2.7.git%3Ba=commit%3Bh=a0e561ad7f29ed50c473f5a9da664267b60d1112https://lists.debian.org/debian-lts-announce/2023/02/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPTJQHKUEU2PQ7RWFUYAFLAD4STEIKHU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JM5NCIBTHYDTLPY2UNC4HO2VAHHE6CJG/https://www.debian.org/security/2023/dsa-5348https://www.haproxy.org/
2023-02-14
Published