VYPR
High severity7.5NVD Advisory· Published Aug 17, 2021· Updated Jun 17, 2026

CVE-2021-39242

CVE-2021-39242

Description

An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Haproxy/Haproxy2 versions
    cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*range: >=2.2.0,<2.2.16
    • (no CPE)range: <2.2.16, <2.3.13, <2.4.3
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • HAProxy/HAProxydescription
  • Debian/haproxyllm-create
  • osv-coords
    Range: >= 2.2.0, < 2.2.16

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.