An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
https://www.mail-archive.com/haproxy%40formilux.org/msg41114.html
https://www.mail-archive.com/haproxy%40formilux.org
https://www.debian.org/security/2021/dsa-4968
https://github.com/haproxy/haproxy/commit/3b69886f7dcc3cfb3d166309018e6cfec9ce2c95