CVE-2022-0711: High severity haproxy vulnerability
A flaw was found in haproxy. Anybody who can add a "set-cookie2 X=Y" header into the return path from their server/backend will kill haproxy in 2.2 (and onwards), resulting in a denial of service.
Other sources
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in HAProxy?
The vulnerability ID is CVE-2022-0711.
How does this vulnerability affect HAProxy?
This vulnerability can lead to a denial of service condition in HAProxy.
What is the severity of CVE-2022-0711?
The severity of CVE-2022-0711 is high with a severity value of 7.
What software versions of HAProxy are affected by this vulnerability?
HAProxy versions up to 2.5.1 are affected by this vulnerability.
How can I fix CVE-2022-0711 in HAProxy?
To fix CVE-2022-0711, update HAProxy to version 2.5.2 or later.