CVE-2022-0711: Debian Linux
High severity, CVSS 7.5. EPSS: 16.6% chance of exploitation in the next 30 days.
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
Affected products
- Debian Debian Linux: version 11.0 only
- Haproxy Haproxy: from 2.2.0, before 2.2.21 (fixed in 2.2.21); from 2.3.0, before 2.3.18 (fixed in 2.3.18); from 2.4.0, before 2.4.13 (fixed in 2.4.13)
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Red Hat Openshift Container Platform: version 4.0 only
- Red Hat Software Collections: affected versions not specified
Published 2022-03-02. Last modified 2026-06-17.