CVE-2026-93302
- EPSS 0.36%
- Veröffentlicht 27.09.2026 09:07:35
- Zuletzt bearbeitet 02.10.2026 18:57:08
MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_ce...
CVE-2026-90678
- EPSS 0.52%
- Veröffentlicht 13.09.2026 03:37:55
- Zuletzt bearbeitet 22.09.2026 19:56:19
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a...
CVE-2026-26081
- EPSS 0.36%
- Veröffentlicht 20.07.2026 00:00:00
- Zuletzt bearbeitet 25.08.2026 15:43:31
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
CVE-2026-26080
- EPSS 0.42%
- Veröffentlicht 20.07.2026 00:00:00
- Zuletzt bearbeitet 25.08.2026 15:43:56
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
CVE-2026-55204
- EPSS 0.48%
- Veröffentlicht 18.06.2026 16:05:52
- Zuletzt bearbeitet 14.07.2026 22:17:17
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attack...
CVE-2026-55203
- EPSS 0.35%
- Veröffentlicht 18.06.2026 16:05:20
- Zuletzt bearbeitet 14.07.2026 22:17:17
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the ...
CVE-2026-33555
- EPSS 0.3%
- Veröffentlicht 13.04.2026 00:00:00
- Zuletzt bearbeitet 29.06.2026 15:28:15
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronizatio...
CVE-2026-5501
- EPSS 0.18%
- Veröffentlicht 10.04.2026 04:17:17
- Zuletzt bearbeitet 27.04.2026 17:57:21
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by ...
CVE-2025-11230
- EPSS 0.69%
- Veröffentlicht 19.11.2025 09:28:39
- Zuletzt bearbeitet 19.12.2025 16:44:55
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
CVE-2025-32464
- EPSS 0.72%
- Veröffentlicht 09.04.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.