CVE-2023-40225: Haproxy

High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.

HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.

Affected products

  • Haproxy Haproxy: up to and including 2.0.32; from 2.2.0, up to and including 2.2.30; from 2.4.0, up to and including 2.4.23; from 2.5.0, before 2.6.15 (fixed in 2.6.15); from 2.7.0, before 2.7.10 (fixed in 2.7.10); from 2.8.0, before 2.8.2 (fixed in 2.8.2)

Published 2023-08-10. Last modified 2026-06-17.