CVE-2024-53008: Haproxy

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.

Affected products

  • Haproxy Haproxy: from 2.6, up to and including 2.6.18; from 2.8, up to and including 2.8.10; from 2.9, up to and including 2.9.9; from 3.0, up to and including 3.0.2
  • Haproxy Project Haproxy 2.6: up to and including 2.6.18
  • Haproxy Project Haproxy 2.8: up to and including 2.8.10
  • Haproxy Project Haproxy 2.9: up to and including 2.9.9
  • Haproxy Project Haproxy 3.0: up to and including 3.0.2

Published 2024-11-28. Last modified 2026-06-17.