Impact
The vulnerability arises when HAProxy, built with QUIC support and configured with an HTTP/3 frontend, estimates the payload length from a DATA frame header before the payload arrives and emits that length as an HTTP/1.1 chunk size. If the declared length exceeds the data written, HAProxy announces a chunk larger than the bytes it writes, leaving the connection in a desynchronized state. This can smuggle a request past HAProxy’s HTTP analysis, allowing an attacker to inject a request that is later interpreted by the backend as the body of a concurrent client request, potentially bypassing access controls and corrupting session data.
Affected Systems
The flaw affects HAProxy versions 3.3.0 through 3.4.4 and the development releases 3.5‑dev1 through 3.5‑dev5. The issue is only exploitable when the binary is built with QUIC support and a QUIC bind listener is configured for an HTTP/3 frontend. Earlier releases in the 3.2 branch and below are immune.
Risk and Exploitability
The potential for request smuggling and subsequent loss of confidentiality, integrity, and availability of other connections. EPSS not listed in the CISA KEV catalogue, suggesting a low exploitation probability at present. The exploit requires a remote, unauthenticated client to send an HTTP/3 request with a mismatched payload size and to time the transmission such that the it is nondeterministic but can be repeated freely once conditions are met.
OpenCVE Enrichment