VYPR
High severity7.3NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026

CVE-2023-25950

CVE-2023-25950

Description

HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Haproxy/Haproxy4 versions
    cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*range: >=2.6.1,<=2.6.7
    • cpe:2.3:a:haproxy:haproxy:2.7.0:*:*:*:*:*:*:*
    • (no CPE)range: 2.7.0, 2.6.1 to 2.6.7
    • (no CPE)range: version 2.7.0, and version 2.6.1 to 2.6.7
  • osv-coords
    Range: >= 2.6.1, < 2.6.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.