{"id":"CVE-2022-0711","details":"A flaw was found in the way HAProxy processed HTTP responses containing the \"Set-Cookie2\" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.","aliases":["BIT-haproxy-2022-0711"],"modified":"2026-09-12T14:19:14.309063Z","published":"2022-03-02T21:59:03Z","related":["SUSE-SU-2022:2277-1","openSUSE-SU-2024:11876-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0711.json","cna_assigner":"redhat","cwe_ids":["CWE-835"]},"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2022-0711"},{"type":"WEB","url":"https://www.mail-archive.com/haproxy%40formilux.org/msg41833.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0711.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0711"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5102"},{"type":"FIX","url":"https://github.com/haproxy/haproxy/commit/bfb15ab34ead85f64cd6da0e9fb418c9cd14cee8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/haproxy/haproxy","events":[{"introduced":"6cbbecf09734aeb5fa8bb88f36f06a6f6d35e813"},{"fixed":"09cc669afb35fa362c9e42ab42c85f21cbdecd9d"},{"fixed":"bfb15ab34ead85f64cd6da0e9fb418c9cd14cee8"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.0"},{"fixed":"2.4.13"}]}}],"versions":["2.5.1","v2.6-dev1","v2.6-dev0","v2.5.0","v2.5-dev15","v2.5-dev14","v2.5-dev13","v2.5-dev12","v2.5-dev11","v2.5-dev10","v2.5-dev9","v2.5-dev8","v2.5-dev7","v2.5-dev6","v2.5-dev5","v2.5-dev4","v2.5-dev3","v2.5-dev2","v2.5-dev1","v2.5-dev0","v2.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-0711.json","vanir_signatures_modified":"2026-09-12T14:19:14Z","vanir_signatures":[{"target":{"file":"src/http_ana.c"},"deprecated":false,"digest":{"line_hashes":["337496346880649468093710429442135291026","100471815415007832791994411618091627129","319132254654960409829937430810655726392","322735852155913190660686993841847730435"],"threshold":0.9},"id":"CVE-2022-0711-639036d4","signature_type":"Line","signature_version":"v1","source":"https://github.com/haproxy/haproxy/commit/bfb15ab34ead85f64cd6da0e9fb418c9cd14cee8"},{"source":"https://github.com/haproxy/haproxy/commit/bfb15ab34ead85f64cd6da0e9fb418c9cd14cee8","target":{"file":"src/http_ana.c","function":"http_manage_server_side_cookies"},"deprecated":false,"digest":{"function_hash":"98329939681248038118576851848161614349","length":3914},"id":"CVE-2022-0711-b396e60b","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0"}