CVE-2023-40225
Last modified
CVE-2023-40225 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.. EPSS estimates a 1.81% chance of exploitation in the next 30 days.
Description
HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Haproxy | Haproxy | <= 2.0.32 |
| Haproxy | Haproxy | >= 2.2.0, <= 2.2.30 |
| Haproxy | Haproxy | >= 2.4.0, <= 2.4.23 |
| Haproxy | Haproxy | >= 2.5.0, < 2.6.15 |
| Haproxy | Haproxy | >= 2.7.0, < 2.7.10 |
| Haproxy | Haproxy | >= 2.8.0, < 2.8.2 |
References
- https://cwe.mitre.org/data/definitions/436.htmlTechnical Description
- https://github.com/haproxy/haproxy/issues/2237Exploit, Issue Tracking, Vendor Advisory
- https://www.haproxy.org/download/2.6/src/CHANGELOGRelease Notes
- https://www.haproxy.org/download/2.7/src/CHANGELOGRelease Notes
- https://www.haproxy.org/download/2.8/src/CHANGELOGRelease Notes
- https://cwe.mitre.org/data/definitions/436.htmlTechnical Description
- https://github.com/haproxy/haproxy/issues/2237Exploit, Issue Tracking, Vendor Advisory
- https://www.haproxy.org/download/2.6/src/CHANGELOGRelease Notes
- https://www.haproxy.org/download/2.7/src/CHANGELOGRelease Notes
- https://www.haproxy.org/download/2.8/src/CHANGELOGRelease Notes
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40225?
How severe is CVE-2023-40225?
How do I fix CVE-2023-40225?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4022The Herd Effects WordPress plugin before 5.2.3 does not sani…4.8
- CVE-2023-40220Improper buffer restrictions in some Intel(R) NUC BIOS firmw…4.4
- CVE-2023-40221 The absence of filters when loading some sectio…8.8
- CVE-2023-40222In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (120…8.4
- CVE-2023-40223Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-40224MISP 2.4.174 allows XSS in app/View/Events/index.ctp.6.1
- CVE-2023-4023The All Users Messenger WordPress plugin through 1.24 does n…4.3
- CVE-2023-40235An NTLM Hash Disclosure was discovered in ArchiMate Archi be…6.5
- CVE-2023-40236In Pexip VMR self-service portal before 3, the same SSH host…5.3
- CVE-2023-40238A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde I…5.5
- CVE-2023-40239Certain Lexmark devices (such as CS310) before 2023-08-25 al…7.5
- CVE-2023-4024The Radio Player plugin for WordPress is vulnerable to unaut…5.3
Are you affected by CVE-2023-40225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
