Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-40346

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.923
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
References
Products affected by CVE-2021-40346


Contact Us

Shodan ® - All rights reserved