Collected research
Integer overflow vulnerability in HAProxy
Critical Vulnerability in HAProxy (CVE-2021-40346): Integer Overflow Enables HTTP Smuggling
HAProxy stored an HTTP header's name length in only 8 bits, so a 270-byte header name overflowed the field and the second processing phase read a different, shorter name than the parsing phase did. A crafted request thereby gains a second Content-Length that HAProxy forwards, letting an attacker smuggle a whole request past HAProxy's ACLs to the backend.
Record
- Document
- Critical Vulnerability in HAProxy (CVE-2021-40346): Integer Overflow Enables HTTP Smuggling
- Researcher
- daniellea, @jfrog and Ori Hollander and Or Peles
- Published by
- JFrog
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of daniellea, @jfrog and Ori Hollander and Or Peles, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .