CVE-2021-39242
HAProxy vulnerability analysis and mitigation

Overview

CVE-2021-39242 is a security vulnerability discovered in HAProxy versions 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. The vulnerability allows an attacker to control HTTP Host headers due to mishandling of mismatches between Host and authority fields (CVE Mitre, NVD).

Technical details

The vulnerability stems from a mismatch handling between the HTTP Host header and the :authority field in HTTP/2 communications. The HTTP/2 specification allows the Host header and the :authority header field to differ, which creates an ambiguous situation where rules built based on the Host field might match against a different Host header field that gets dropped when forwarded to an HTTP/2 backend server (HAProxy Mail).

Impact

When exploited, this vulnerability could allow an attacker to control HTTP Host headers and potentially bypass backend selection logic. This could lead to requests being routed to unintended backend servers, potentially compromising the security of the routing infrastructure (HAProxy Mail).

Mitigation and workarounds

Several mitigation strategies are available: 1) Disable HTTP/2 communication with servers by removing 'proto h2' from server lines, 2) Place 'http-request set-uri %[url]' at the beginning of every HTTP frontend, 3) Disable HTTP/2 processing entirely by setting 'tune.h2.max-concurrent-streams 0' in the global section, or 4) Update to patched versions: 2.2.16, 2.3.13, or 2.4.3 or later (HAProxy Mail, Fedora Update).

Additional resources


SourceThis report was generated using AI

Related HAProxy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11230HIGH7.5
  • HAProxyHAProxy
  • haproxy
NoYesNov 19, 2025
CVE-2025-4953HIGH7.4
  • PodmanPodman
  • container-tools:rhel8::python3-podman
NoYesSep 16, 2025
CVE-2025-32464MEDIUM6.8
  • HAProxyHAProxy
  • haproxy
NoYesApr 09, 2025
CVE-2025-59303MEDIUM6.4
  • HAProxyHAProxy
  • haproxy
NoNoOct 08, 2025
CVE-2024-53008MEDIUM5.3
  • HAProxyHAProxy
  • haproxy-2.8
NoYesNov 28, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management