Web Hack List

Collected research

Integer overflow vulnerability in HAProxy

Critical Vulnerability in HAProxy (CVE-2021-40346): Integer Overflow Enables HTTP Smuggling

HAProxy stored an HTTP header's name length in only 8 bits, so a 270-byte header name overflowed the field and the second processing phase read a different, shorter name than the parsing phase did. A crafted request thereby gains a second Content-Length that HAProxy forwards, letting an attacker smuggle a whole request past HAProxy's ACLs to the backend.

Record

Document
Critical Vulnerability in HAProxy (CVE-2021-40346): Integer Overflow Enables HTTP Smuggling
Researcher
daniellea, @jfrog and Ori Hollander and Or Peles
Published by
JFrog
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of daniellea, @jfrog and Ori Hollander and Or Peles, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .