CVE & CISA-KEV Catalog

CVE-2019-18277

HIGHEPSS 95th pctl
7.5
CVSS v3
NVD

Description

A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).

How to fix

Remediation Available
haproxyDebian
Fixed in:2.0.6-1CVE-2019-18277
Fixed in:2.0.6-1CVE-2019-18277
Fixed in:2.0.6-1CVE-2019-18277
Fixed in:2.0.6-1CVE-2019-18277
haproxyUbuntu
Fixed in:1.6.3-1ubuntu0.3USN-4174-1
Fixed in:1.8.8-1ubuntu0.7USN-4174-1

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityHigh
AvailabilityNone

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Exploit Intelligence

10.02%probability of exploitation in 30 days
95thpercentile

Very high risk: more likely to be exploited than 95% of all known CVEs.

References

Related Vulnerabilities

Other CWE-444 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2022-22536Critical10.098%KEV-
CVE-2025-61884High7.598%KEV + Ransom-
CVE-2020-9490High7.590%-Fix
CVE-2023-41265Critical9.685%KEV + Ransom-
CVE-2023-25690Critical9.884%-Fix
CVE-2022-32214Medium6.581%-Fix
Embed a live status badge for CVE-2019-18277
CVE-2019-18277 severity badge

Markdown

[![CVE-2019-18277](https://tridentstack.com/cve/badge/CVE-2019-18277.svg)](https://tridentstack.com/cve/CVE-2019-18277)

HTML

<a href="https://tridentstack.com/cve/CVE-2019-18277"><img src="https://tridentstack.com/cve/badge/CVE-2019-18277.svg" alt="CVE-2019-18277"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.