CRITICAL 9.1 Microsoft PoC

CVE-2023-25725

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3 the impact is limited because the headers disappear before being parsed and processed as if they had not been sent by the client. The fixed versions are 2.7.3 2.6.9 2.5.12 2.4.22 2.2.29 and 2.0.31.

Microsoft Security Update 2023-Feb: HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3 the impact is limited because the headers disappear before being parsed and processed as if they had not been sent by the client. The fixed versions are 2.7.3 2.6.9 2.5.12 2.4.22 2.2.29 and 2.0.31.

Affected Products

References

Published: 2023-02-14 · Source: Microsoft · Feed updated: 2026-08-20
This critical severity vulnerability with a CVSS score of 9.1 was published on 2023-02-14 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 5.5% (top 8% of all CVEs by exploitation probability). Affected: cm1 haproxy 2.1.5-2 on CBL Mariner 1.0, cbl2 haproxy 2.4.22-1 on CBL Mariner 2.0.

Risk Timeline

CVE Disclosed2023-02-14 · 1283 days ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2021-43267 PoCAn issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16.CRITICAL9.8
CVE-2021-43523In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters iCRITICAL9.6
CVE-2020-25632A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation alHIGH8.2
CVE-2021-3935When PgBouncer is configured to use "cert" authentication a man-in-the-middle atHIGH8.1
CVE-2021-3968Heap-based Buffer Overflow in vim/vimHIGH8.0
CVE-2020-12657An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-fHIGH7.8
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.