{"id":"CVE-2023-40225","details":"HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.","aliases":["BIT-haproxy-2023-40225"],"modified":"2026-09-12T14:19:11.449040Z","published":"2023-08-10T00:00:00Z","related":["ALSA-2024:1142","SUSE-SU-2023:3469-1","SUSE-SU-2023:3490-1","SUSE-SU-2023:4646-1","openSUSE-SU-2024:13116-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40225.json","unresolved_ranges":[{"extracted_events":[{"fixed":"2.0.32"},{"introduced":"2.2.x"},{"fixed":"2.2.30"},{"introduced":"2.4.x"},{"fixed":"2.4.23"},{"introduced":"2.6.x"},{"fixed":"2.6.15"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/436.html"},{"type":"WEB","url":"https://www.haproxy.org/download/2.6/src/CHANGELOG"},{"type":"WEB","url":"https://www.haproxy.org/download/2.7/src/CHANGELOG"},{"type":"WEB","url":"https://www.haproxy.org/download/2.8/src/CHANGELOG"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40225.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40225"},{"type":"REPORT","url":"https://github.com/haproxy/haproxy/issues/2237"},{"type":"FIX","url":"https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/haproxy/haproxy","events":[{"introduced":"437fd289f2e32e56498d2d4da63852d483f284ef"},{"fixed":"0279df9e824723004b27cae2d4a04a7b1b924202"},{"introduced":"fdd8154ed37fef7f351075caa357917f94704dd7"},{"fixed":"0f29b34e0a06cdd59ae2278d33c16f63ca435468"},{"fixed":"6492f1f29d738457ea9f382aca54537f35f9d856"}],"database_specific":{"cpe":"cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.7.0"},{"fixed":"2.7.10"},{"introduced":"2.8.0"},{"fixed":"2.8.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.9-dev2","v2.9-dev1","v2.9-dev0","v2.8.0","v2.8-dev1","v2.8-dev0","v2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-40225.json","vanir_signatures_modified":"2026-09-12T14:19:11Z","vanir_signatures":[{"target":{"file":"src/http.c","function":"http_parse_cont_len_header"},"deprecated":false,"digest":{"function_hash":"233598116403124394327874341684154081692","length":920},"id":"CVE-2023-40225-321cb63a","signature_type":"Function","signature_version":"v1","source":"https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856"},{"source":"https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856","target":{"file":"src/h1.c"},"deprecated":false,"digest":{"line_hashes":["165144268708067503662197180751835168325","181476966816870361302138927755052419995","38169904124979107543682445298778353719","90172390201955149448003837056493578792","190028181374243338045588907346606455051","107505088545251584894189210534290438397","331204091758823654164950303515118093648","236794157206778696007620946270386607677","252811914131326760711167158666797745135","31722181914028338651024671069621308286","150844051917068265160765471746425755346","286321739378888021026416454718199891256"],"threshold":0.9},"id":"CVE-2023-40225-6bc15f13","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856","target":{"file":"src/http.c"},"deprecated":false,"digest":{"line_hashes":["72171713211711176057473768202252814200","63927162197679533977345581072990894618","94110014460971723384658371440440144532","90172390201955149448003837056493578792","190028181374243338045588907346606455051","107505088545251584894189210534290438397","331204091758823654164950303515118093648","236794157206778696007620946270386607677","17986306145591369186963995970127593066","285864856605371214411020876314555345112","283123263476167121878797278369257674902","301864301687022632947606540948909654137"],"threshold":0.9},"id":"CVE-2023-40225-e91d6762","signature_type":"Line"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856","target":{"file":"src/h1.c","function":"h1_parse_cont_len_header"},"deprecated":false,"digest":{"function_hash":"228028521571946842552203437083185495676","length":1001},"id":"CVE-2023-40225-f584ff7d"}]}}],"schema_version":"1.9.0"}