Vulnerability record · CVE-2021-40346 · published 8 September 2021
CVE-2021-40346: HAProxy integer overflow in htx_add_header enables HTTP request smuggling
Haproxy · Haproxy
HAProxy 2.0 through 2.5 contains an integer overflow in htx_add_header that lets an attacker craft requests which are parsed inconsistently between HAProxy and backend servers. This request smuggling condition allows bypass of configured http-request HAProxy ACLs and possibly other ACLs, undermining access control enforced at the proxy.
Description
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityNetwork-reachable, no authentication or interaction required, high EPSS and public exploit detail, but no KEV listing and impact is limited to integrity per the CVSS vector.
What it is
HAProxy 2.0 through 2.5 contains an integer overflow in htx_add_header that lets an attacker craft requests which are parsed inconsistently between HAProxy and backend servers. This request smuggling condition allows bypass of configured http-request HAProxy ACLs and possibly other ACLs, undermining access control enforced at the proxy.
Impact
An attacker can smuggle requests past HAProxy ACL rules, reaching backend services or endpoints that the proxy was configured to block. The CVSS vector shows high integrity impact with no confidentiality or availability impact.
Attack surface
Reachable over the network via HTTP requests to an HAProxy instance; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Exploitation depends on the proxy forwarding to a backend that parses the smuggled request differently.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.579 (99th percentile), and a public JFrog blog reference is tagged Exploit, indicating public exploitation detail exists. No ransomware group usage is documented in the record.
What to do
- Upgrade HAProxy to a fixed release; apply the vendor patch referenced in the HAProxy git commit and vendor advisory.
- Update distribution packages on Debian and Fedora using the referenced DSA-4968 and Fedora package announcements.
- Until patched, apply the mitigations described in the JFrog advisory, such as rejecting or normalizing requests with ambiguous Content-Length/Transfer-Encoding handling.
- Review and tighten backend parsing behavior so HAProxy and origin servers agree on request framing.
- Audit http-request ACLs to identify rules that would be bypassed if smuggling succeeds.
Detection
- Inspect proxy and backend logs for requests where Content-Length and Transfer-Encoding disagree or where duplicate/oversized headers appear.
- Hunt for HTTP requests with unusually large or malformed header lengths that could trigger the htx_add_header integer overflow.
- Correlate HAProxy access logs with backend logs to find requests seen by one tier but not the other, a smuggling indicator.
- Monitor for ACL-bypass patterns where requests reach backends that proxy rules should have blocked.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-40346 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40346), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.