Back

HIGH

haproxy: Denial of service via set-cookie2 header

Published Mar 2, 2022

Description

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Affected products

Remediation

Red Hat statement

This issue was introduced in HAProxy 1.9 with the Native HTTP Representation (HTX). Red Hat Enterprise Linux 6, 7, 8 and Red Hat Software Collections are not affected by this flaw, as they ship older versions of `haproxy` which do not include support for HTX.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 2, 2022
Updated Aug 2, 2024
Reserved Feb 21, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 23, 2022
ENISA EUVD
Assigner redhat
Published Mar 2, 2022
Updated Aug 2, 2024
Exploited since n/a
EUVD-2022-15786