CVE-2023-25725: Critical severity HAProxy HAProxy vulnerability

Published Feb 11, 2023
·
Updated

A flaw was found in HAProxy's headers processing that causes HAProxy to drop important headers fields such as Connection, Content-length, Transfer-Encoding, and Host after having partially processed them. A maliciously crafted HTTP request could be used in an HTTP request smuggling attack to bypass filtering and detection by HAProxy.

Other sources

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.

I will attach the patch to this flaw, but there may be an even newer patch available from the reporter (Willy Tarreau).

Summary from the initial report: There is a serious bug in haproxy's HTTP/1 header parser which unfortunately accepts an empty header name ... The impact is that some mandatory headers could be dropped after their presence was confirmed ... resulting in a request smuggling attack. Also this empty header could be used to make a transfer-encoding or content-length disappear while the internal parser still thinks it's there since it was seen ... I guess some (attackers) might be creative enough to exploit it ...

The fix ... applies well as far as v2.0 ...

I would like to propose an early coordinated release date ... Tuesday 14th 7pm CET ... it shouldn't take long to some attackers to figure how to exploit this to bypass some URL checks

Red Hat

Affected Software

22 affected componentsFixes available
redhat/haproxy<0:2.4.17-3.el9_1.2
0:2.4.17-3.el9_1.2
redhat/haproxy<0:2.4.7-2.el9_0.2
0:2.4.7-2.el9_0.2
redhat/haproxy<0:2.2.19-4.el8
0:2.2.19-4.el8
redhat/haproxy<0:2.2.24-3.rhaos4.11.el8
0:2.2.24-3.rhaos4.11.el8
redhat/haproxy<0:2.2.24-3.rhaos4.12.el8
0:2.2.24-3.rhaos4.12.el8
redhat/haproxy<0:2.2.24-3.rhaos4.13.el8
0:2.2.24-3.rhaos4.13.el8
redhat/HAProxy<2.0.31
2.0.31
redhat/HAProxy<2.2.29
2.2.29
redhat/HAProxy<2.4.22
2.4.22
redhat/HAProxy<2.5.12
2.5.12
redhat/HAProxy<2.6.9
2.6.9
redhat/HAProxy<2.7.3
2.7.3
redhat/HAProxy<2.8
2.8
HAProxy HAProxy<2.0.31
HAProxy HAProxy>=2.1.0<2.2.29
HAProxy HAProxy>=2.3.0<2.4.22
HAProxy HAProxy>=2.5.0<2.5.12
HAProxy HAProxy>=2.6.0<2.6.9
HAProxy HAProxy>=2.7.0<2.7.3
Debian Debian Linux=10.0
Debian Debian Linux=11.0
debian/haproxy
2.2.9-2+deb11u62.2.9-2+deb11u72.6.12-1+deb12u33.0.11-1+deb13u33.2.22-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/haproxy to a version that resolves this vulnerability.

    Fixed in 0:2.4.17-3.el9_1.2
  2. Upgrade

    Upgrade redhat/haproxy to a version that resolves this vulnerability.

    Fixed in 0:2.4.7-2.el9_0.2
  3. Upgrade

    Upgrade redhat/haproxy to a version that resolves this vulnerability.

    Fixed in 0:2.2.19-4.el8
  4. Upgrade

    Upgrade redhat/haproxy to a version that resolves this vulnerability.

    Fixed in 0:2.2.24-3.rhaos4.11.el8
  5. Upgrade

    Upgrade redhat/haproxy to a version that resolves this vulnerability.

    Fixed in 0:2.2.24-3.rhaos4.12.el8
  6. Upgrade

    Upgrade redhat/haproxy to a version that resolves this vulnerability.

    Fixed in 0:2.2.24-3.rhaos4.13.el8
  7. Upgrade

    Upgrade redhat/HAProxy to a version that resolves this vulnerability.

    Fixed in 2.0.31
  8. Upgrade

    Upgrade redhat/HAProxy to a version that resolves this vulnerability.

    Fixed in 2.2.29
  9. Upgrade

    Upgrade redhat/HAProxy to a version that resolves this vulnerability.

    Fixed in 2.4.22
  10. Upgrade

    Upgrade redhat/HAProxy to a version that resolves this vulnerability.

    Fixed in 2.5.12
  11. Upgrade

    Upgrade redhat/HAProxy to a version that resolves this vulnerability.

    Fixed in 2.6.9
  12. Upgrade

    Upgrade redhat/HAProxy to a version that resolves this vulnerability.

    Fixed in 2.7.3
  13. Upgrade

    Upgrade redhat/HAProxy to a version that resolves this vulnerability.

    Fixed in 2.8
  14. Upgrade

    Upgrade debian/haproxy to a version that resolves this vulnerability.

    Fixed in 2.2.9-2+deb11u6Fixed in 2.2.9-2+deb11u7Fixed in 2.6.12-1+deb12u3Fixed in 3.0.11-1+deb13u3Fixed in 3.2.22-1
  15. Upgrade

    Upgrade haproxy to a version that resolves this vulnerability.

    Fixed in 2.7.3
  16. Upgrade

    Upgrade haproxy to a version that resolves this vulnerability.

    Fixed in 2.6.9
  17. Upgrade

    Upgrade haproxy to a version that resolves this vulnerability.

    Fixed in 2.5.12
  18. Upgrade

    Upgrade haproxy to a version that resolves this vulnerability.

    Fixed in 2.4.22
  19. Upgrade

    Upgrade haproxy to a version that resolves this vulnerability.

    Fixed in 2.2.29
  20. Upgrade

    Upgrade haproxy to a version that resolves this vulnerability.

    Fixed in 2.0.31

Event History

Feb 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 3, 2024
Data Sourced
via Launchpad·08:41 AM
Description
Dec 7, 2024
Data Sourced
via Ubuntu·08:42 AM
RemedyDescriptionSeverityAffected Software
Aug 2, 2026
Data Sourced
via Debian·02:19 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2023-25725?

CVE-2023-25725 is a vulnerability in HAProxy that allows bypass of access control through request smuggling.

2

What is the severity of CVE-2023-25725?

CVE-2023-25725 has a severity rating of 9.1 (Critical).

3

How does CVE-2023-25725 affect HAProxy?

CVE-2023-25725 affects HAProxy versions before 2.7.3 and may cause the loss of important HTTP/1 headers, leading to a bypass of access control.

4

How can I fix CVE-2023-25725?

To fix CVE-2023-25725, update HAProxy to version 2.7.3 or later.

5

Where can I find more information about CVE-2023-25725?

You can find more information about CVE-2023-25725 at the following references: [Bugzilla - 2169823](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2169823), [Bugzilla - 2170060](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2170060), [Red Hat Security Advisory - CVE-2023-25725](https://access.redhat.com/security/cve/CVE-2023-25725).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203