AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-39241

MEDIUM · CVSS 5.3 EPSS 1.77%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-08-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-39241
Severity
MEDIUM
CVSS
5.3
EPSS
1.77%

Original NVD Description

An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.