Impact
HAProxy Community Edition versions 3.0 through 3.3, as well as Enterprise and ALOHA, process the NEW_TOKEN format without a length check. An attacker can send tokens of arbitrary size, potentially causing buffer overflows and memory corruption, which could lead to crashes or unintended behavior. The weakness is classified as CWE-130.
Affected Systems
All HAProxy instances based on Community Edition, Enterprise, or ALOHA with versions 3.0 up to, but not including, 3.3.3 are affected.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium severity risk. The EPSS score indicates a probability of exploitation of less than 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting it is not widely exploited yet. Attackers would need to send a request containing a syntactically valid NEW_TOKEN header or parameter with an excessively long value, which is likely feasible over a network-facing interface. The lack of a length guard makes the flaw potentially exploitable for memory corruption or denial of service, but the exact impact remains uncertain without further evidence.
OpenCVE Enrichment
Debian DSA
Ubuntu USN