Fedora Account System
Red Hat Associate
Red Hat Customer
HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request. References: https://www.haproxy.org/download/2.8/src/CHANGELOG https://www.haproxy.org/download/2.6/src/CHANGELOG https://github.com/haproxy/haproxy/issues/2237 https://www.haproxy.org/download/2.7/src/CHANGELOG https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856
Created haproxy tracking bugs for this issue: Affects: fedora-all [bug 2231371] Created haproxy18 tracking bugs for this issue: Affects: epel-7 [bug 2231372]
Please note that HAProxy versions before version 2.0, e.g. 1.8 as shipped in RHEL 8 or 1.5 as shipped in RHEL 7, are also affected. See https://github.com/haproxy/haproxy/issues/2237#issuecomment-1676113850 (and comment replies) for more details.
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2023:7473 https://access.redhat.com/errata/RHSA-2023:7473
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:7606 https://access.redhat.com/errata/RHSA-2023:7606
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:0200 https://access.redhat.com/errata/RHSA-2024:0200
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.11 Via RHSA-2024:0308 https://access.redhat.com/errata/RHSA-2024:0308
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2023:7201 https://access.redhat.com/errata/RHSA-2023:7201
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:1089 https://access.redhat.com/errata/RHSA-2024:1089
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1142 https://access.redhat.com/errata/RHSA-2024:1142