VYPR
Medium severity5.3NVD Advisory· Published Aug 17, 2021· Updated Jun 17, 2026

CVE-2021-39241

CVE-2021-39241

Description

An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Haproxy/Haproxy2 versions
    cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*range: >=2.0.0,<2.0.24
    • (no CPE)range: <2.0.24, <2.2.16, <2.3.13, <2.4.3
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • HAProxy/HAProxydescription
  • osv-coords
    Range: >= 2.0.0, < 2.0.24

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.