CVE-2021-40346 is an integer-overflow vulnerability in the HAProxy htx_add_header function affecting HAProxy versions 2.0 through 2.5. The overflow can be exploited for HTTP request smuggling, enabling an attacker to bypass configured http-request HAProxy ACLs and potentially other ACLs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small self-contained proof-of-concept for CVE-2021-40346, an HAProxy integer overflow vulnerability that enables HTTP request smuggling and ACL bypass. The repo contains 6 files: a README explaining the bug and reproduction steps, a Python PoC (`poc.py`), HAProxy configuration (`haproxy.cfg`), a Docker Compose lab (`docker-compose.yml`), and a minimal Flask backend (`backend/app.py`) with its Dockerfile. The main exploit logic is in `poc.py`. It opens a raw TCP connection to `127.0.0.1:8080` and sends a crafted HTTP POST request. The malicious component is an oversized header name built as `b"Content-Length" + b"0" + b"a" * 255`, making the header name 270 bytes long. Per the vulnerability description, this overflows HAProxy's internal 8-bit header-name length handling so HAProxy effectively misinterprets the crafted header as `Content-Length: 0`. The PoC then appends a legitimate `Content-Length` header for the body size and places a second HTTP request (`GET /admin`) in the body. HAProxy applies ACL checks only to the visible first request (`POST /`) while the backend later interprets the body as a new request to `/admin`, bypassing the frontend deny rule. The lab environment is intentionally simple and realistic: HAProxy 2.2.16 listens on port 80 and is published to host port 8080; the frontend ACL denies requests where `path_beg /admin`; the backend is a Flask/Gunicorn service exposing `/` and `/admin`. This confirms the exploit is not just theoretical: it demonstrates practical ACL bypass against a reverse proxy configuration. There is no post-exploitation payload beyond the smuggled request itself, so the repository is best classified as a network/web PoC exploit rather than a weaponized framework module.
This repository is a proof-of-concept exploit for CVE-2021-40346, an integer overflow vulnerability in HAProxy's HTTP header parsing that enables HTTP request smuggling and ACL bypass. The structure includes: - `attacker/http_smuggler.py`: The main exploit script, written in Python, which crafts and sends a sequence of HTTP requests to a HAProxy instance running on localhost:8080. It first logs in to obtain a session cookie, then performs a two-step request smuggling attack to bypass ACLs and access the protected `/users/admin` endpoint, exposing all user credentials. - `server/server.py`: A Flask-based backend server simulating a web application with user authentication and an admin panel. It logs requests and responses and exposes endpoints for login and admin access. - `server/haproxy.cfg`: The HAProxy configuration, defining ACLs to protect the admin endpoint based on session cookies. - `Dockerfile` and `docker-compose.yml`: Used to set up the backend and proxy environment for testing the exploit. - `readme.md`: Documentation describing the vulnerability and usage. The exploit demonstrates a real-world attack scenario where an attacker can bypass HAProxy's access controls using HTTP request smuggling, ultimately retrieving sensitive information from a protected admin panel. The code is a functional proof-of-concept and not weaponized for mass exploitation.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2021-40346, a HTTP request smuggling vulnerability in HAProxy (tested on version 2.4.3). The repository contains a Dockerfile to set up a test environment with HAProxy and a simple Node.js backend (app.js). The HAProxy configuration (haproxy.cfg) denies direct access to the /admin path, but the provided payload (payload.txt) demonstrates how a specially crafted HTTP request can bypass this restriction via HTTP request smuggling. The exploit works by sending a malformed HTTP request that causes HAProxy to misinterpret the boundaries of HTTP requests, forwarding a forbidden /admin request to the backend server. The README provides setup and testing instructions, confirming the exploit's effect by observing backend logs. The main attack vector is network-based, targeting HTTP traffic through a misconfigured or vulnerable HAProxy instance. The endpoints involved are the local test server (http://localhost:8000), the /admin path, and the backend server at 127.0.0.1:8000. The exploit is educational and demonstrates the impact of CVE-2021-40346 in a controlled environment.
This repository is a proof-of-concept (POC) exploit for CVE-2021-40346, an integer overflow vulnerability in HAProxy that enables HTTP request smuggling. The repository contains a Docker-based setup with HAProxy (v2.2.16) and a simple Flask backend exposing /guest and /admin endpoints. The HAProxy configuration denies direct access to /admin, but the provided payload demonstrates how a specially crafted HTTP request can exploit the integer overflow to bypass this restriction and access /admin via HTTP smuggling. The main exploit logic is in the 'payload' file, which contains a raw HTTP request with manipulated Content-Length headers. The repository is structured for easy setup and demonstration of the vulnerability, with configuration files for HAProxy and Docker, a minimal Flask app, and the exploit payload. No detection scripts or fake elements are present; this is a functional POC for the described vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.