cbcvebase.
CVE-2023-25725
published 2023-02-14

CVE-2023-25725: HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP…

PriorityP356critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
5.49%
91.9th percentile
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianhaproxy< haproxy 2.6.8-2 (bookworm)haproxy 2.6.8-2 (bookworm)
haproxyhaproxy< 2.0.312.0.31
haproxyhaproxy>= 0 < 2.2.9-2+deb11u42.2.9-2+deb11u4
haproxyhaproxy>= 0 < 2.6.8-22.6.8-2
haproxyhaproxy>= 0 < 2.6.8-22.6.8-2
haproxyhaproxy>= 0 < 2.6.8-22.6.8-2
haproxyhaproxy>= 2.1.0 < 2.2.292.2.29
haproxyhaproxy>= 2.3.0 < 2.4.222.4.22
haproxyhaproxy>= 2.5.0 < 2.5.122.5.12
haproxyhaproxy>= 2.6.0 < 2.6.92.6.9
haproxyhaproxy>= 2.7.0 < 2.7.32.7.3
msrccbl2_haproxy_2.4.22-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_haproxy_2.1.5-2_on_cbl_mariner_1.0

Detection & IOCsextracted from sources · hover to see the quote

  • Detect HTTP requests with empty header field names sent to HAProxy, which can be used to truncate the HTTP header list and smuggle headers past access controls
  • Monitor for HTTP request smuggling attempts targeting HAProxy that cause critical headers (Connection, Content-length, Transfer-Encoding, Host) to be dropped mid-processing
  • Focus smuggling detection on HTTP/1.0 and HTTP/1.1 traffic to HAProxy; HTTP/2 and HTTP/3 are lower risk as headers disappear before parsing rather than after
  • ·HAProxy versions before 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31 are vulnerable; verify deployed version is patched to one of these fixed releases

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.