VYPR
High severity7.5NVD Advisory· Published Aug 17, 2021· Updated Jun 17, 2026

CVE-2021-39240

CVE-2021-39240

Description

An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field (as observed on a target HTTP/2 server) might differ from what the routing rules were intended to achieve.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Haproxy/Haproxy2 versions
    cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*range: >=2.2.0,<2.2.16
    • (no CPE)range: <2.2.16, <2.3.13, <2.4.3
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • HAProxy/HAProxydescription
  • osv-coords2 versions
    >= 2.2.0, < 2.2.16+ 1 more
    • (no CPE)range: >= 2.2.0, < 2.2.16
    • (no CPE)range: < 2.4.4+git0.acb1d0bea-1.2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.