Web Hack List

Other nomination

Integer overflow vulnerability in HAProxy

HAProxy stored an HTTP header's name length in only 8 bits, so a 270-byte header name overflowed the field and the second processing phase read a different, shorter name than the parsing phase did. A crafted request thereby gains a second Content-Length that HAProxy forwards, letting an attacker smuggle a whole request past HAProxy's ACLs to the backend.

Record

Researcher
daniellea, @jfrog and Ori Hollander and Or Peles
Published by
JFrog
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of daniellea, @jfrog and Ori Hollander and Or Peles, first published at the original source. Preserved copies are kept so the citation survives its host.