Back

HIGH

haproxy: HTTP request smuggling issue with transfer-encoding header containing an obfuscated "chunked" value

Published Oct 23, 2019

Description

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

Affected products

Remediation

Red Hat statement

To exploit this vulnerability a vulnerable backend server is required. In particular the server should incorrectly parse the Transfer-Encoding HTTP header. This issue did not affect the versions of haproxy as shipped with Red Hat Enterprise Linux 6, and 7 as they did not include support for `http-reuse` option.

Red Hat mitigation

- Reconsider the use of `http-reuse always` if possible - Disable HTTP Keep-Alive (also called HTTP Connection reuse) in the backend - Fix the backend server to correctly parse Transfer-Encoding/Content-Length headers

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2019
Updated Aug 5, 2024
Reserved Oct 23, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 13, 2019