Haproxy

Haproxy

42 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 27.09.2026 09:07:35
  • Zuletzt bearbeitet 02.10.2026 18:57:08

MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_ce...

  • EPSS 0.52%
  • Veröffentlicht 13.09.2026 03:37:55
  • Zuletzt bearbeitet 22.09.2026 19:56:19

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a...

  • EPSS 0.36%
  • Veröffentlicht 20.07.2026 00:00:00
  • Zuletzt bearbeitet 25.08.2026 15:43:31

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

  • EPSS 0.42%
  • Veröffentlicht 20.07.2026 00:00:00
  • Zuletzt bearbeitet 25.08.2026 15:43:56

HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

  • EPSS 0.48%
  • Veröffentlicht 18.06.2026 16:05:52
  • Zuletzt bearbeitet 14.07.2026 22:17:17

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attack...

  • EPSS 0.35%
  • Veröffentlicht 18.06.2026 16:05:20
  • Zuletzt bearbeitet 14.07.2026 22:17:17

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 29.06.2026 15:28:15

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronizatio...

  • EPSS 0.18%
  • Veröffentlicht 10.04.2026 04:17:17
  • Zuletzt bearbeitet 27.04.2026 17:57:21

wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by ...

  • EPSS 0.69%
  • Veröffentlicht 19.11.2025 09:28:39
  • Zuletzt bearbeitet 19.12.2025 16:44:55

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

  • EPSS 0.72%
  • Veröffentlicht 09.04.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.