#VU61291 Infinite loop in HAProxy - CVE-2022-0711
Published: March 14, 2022
HAProxy
HAProxy
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when processing HTTP responses containing the "Set-Cookie2" header. A remote attacker can send a specially crafted HTTP request to the server, consume all available system resources and cause denial of service conditions.