Martino Spagnuolo reported that the HTTP/3 parsing code in HAProxy, a fast and reliable load balancing reverse proxy, does not properly validate the received body size and the announced content-length header, which may result in HTTP request smuggling.
https://security-tracker.debian.org/tracker/DSA-6291-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6291-1
Continue reading...

