Vulnerability record · CVE-2019-14241 · published 23 July 2019
CVE-2019-14241: HAProxy cookie handling flaw triggers ha_panic denial of service
Haproxy · Haproxy
HAProxy through 2.0.2 can be forced into a ha_panic crash through vectors tied to htx_manage_client_side_cookies in proto_htx.c. The flaw is an uncontrolled resource consumption / infinite loop class issue (CWE-835) reachable over the network, so a single crafted request can take down the proxy. Because HAProxy is typically the front door for other services, a crash disrupts all traffic it fronts.
Description
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote crash of a widely deployed front-end proxy with public exploit material and very high EPSS, though no KEV listing or confirmed in-the-wild use.
What it is
HAProxy through 2.0.2 can be forced into a ha_panic crash through vectors tied to htx_manage_client_side_cookies in proto_htx.c. The flaw is an uncontrolled resource consumption / infinite loop class issue (CWE-835) reachable over the network, so a single crafted request can take down the proxy. Because HAProxy is typically the front door for other services, a crash disrupts all traffic it fronts.
Impact
An unauthenticated remote attacker can crash the HAProxy process, causing a denial of service for every service behind it. There is no evidence of data exposure or code execution; the gain is availability loss.
Attack surface
Reached over the network via HTTP traffic that exercises client-side cookie handling in the HTX path; the CVSS vector shows no privileges and no user interaction required. Any deployment exposing HAProxy to untrusted clients is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.7024 probability, 99.3rd percentile) and a GitHub issue reference is tagged Exploit, indicating public proof-of-concept material exists. No confirmed in-the-wild exploitation is documented in this record.
What to do
- Upgrade HAProxy to a version after 2.0.2 that contains the fix for the htx_manage_client_side_cookies issue; patch first.
- If immediate upgrade is not possible, apply vendor or distribution backports (for example the referenced openSUSE security advisories) rather than waiting.
- Restrict or filter untrusted HTTP traffic reaching HAProxy where feasible, and rate-limit clients to reduce crash-triggering request volume.
- Run HAProxy under a supervisor or process manager that restarts it automatically, and place redundant instances behind a load balancer to limit single-crash impact.
- Monitor upstream HAProxy advisories and the referenced GitHub issue for updated guidance.
Detection
- Alert on HAProxy process restarts, ha_panic log entries, or crash dumps correlated with inbound HTTP requests.
- Search HAProxy logs for requests involving cookie headers immediately preceding a restart or panic.
- Track availability gaps or connection resets at the proxy tier that coincide with a single client or source IP.
- Baseline normal request rates and flag spikes in cookie-bearing requests from individual sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00060.html | |
| http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00062.html | |
| http://www.securityfocus.com/bid/109352 | Third Party AdvisoryVDB Entry |
| https://github.com/haproxy/haproxy/issues/181 | ExploitThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00060.html | |
| http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00062.html | |
| http://www.securityfocus.com/bid/109352 | Third Party AdvisoryVDB Entry |
| https://github.com/haproxy/haproxy/issues/181 | ExploitThird Party Advisory |
Track CVE-2019-14241 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-14241), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.