📦 Haproxy

by Haproxy

🔍 What is Haproxy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-25725

CRITICAL CVSS 9.1 Feb 14, 2023

CVE-2023-25725 is an HTTP request smuggling vulnerability in HAProxy that allows attackers to bypass access controls by sending specially crafted HTTP headers. The vulnerability occurs because HAProxy...

CVE-2025-11230

HIGH CVSS 7.5 Nov 19, 2025

This vulnerability in HAProxy's mjson library allows remote attackers to cause denial of service through inefficient algorithm complexity when processing specially crafted JSON requests. Any HAProxy d...

CVE-2024-45506

HIGH CVSS 7.5 Sep 4, 2024

HAProxy HTTP/2 zero-copy forwarding vulnerability allows remote attackers to cause denial of service by exploiting a loop condition in the h2_send function. This affects HAProxy 2.9.x before 2.9.10, 3...

CVE-2023-40225

HIGH CVSS 7.2 Aug 10, 2023

HAProxy versions through multiple branches forward empty Content-Length headers, violating HTTP standards. This can cause HTTP/1 servers behind HAProxy to misinterpret requests, potentially treating p...

CVE-2023-25950

HIGH CVSS 7.3 Apr 11, 2023

This HTTP request smuggling vulnerability in HAProxy allows attackers to manipulate legitimate user requests by exploiting improper request/response handling. Attackers can potentially steal sensitive...

CVE-2022-0711

HIGH CVSS 7.5 Mar 2, 2022

CVE-2022-0711 is a denial-of-service vulnerability in HAProxy where specially crafted HTTP responses containing Set-Cookie2 headers can trigger an infinite loop, causing the service to become unrespon...

CVE-2021-40346

HIGH CVSS 7.5 Sep 8, 2021

CVE-2021-40346 is an integer overflow vulnerability in HAProxy's HTTP header processing that enables HTTP request smuggling attacks. This allows attackers to bypass HAProxy's security ACLs (access con...

CVE-2021-39240

HIGH CVSS 7.5 Aug 17, 2021

HAProxy versions before 2.2.16, 2.3.13, and 2.4.3 have a URI validation vulnerability where the proxy fails to properly validate scheme and path characters in HTTP/2 requests. This allows attackers to...

CVE-2021-39242

HIGH CVSS 7.5 Aug 17, 2021

This vulnerability in HAProxy allows attackers to manipulate HTTP Host headers to bypass security controls or cause request processing errors. It affects HAProxy versions 2.2 before 2.2.16, 2.3 before...

CVE-2023-0056

MEDIUM CVSS 6.5 Mar 23, 2023

An uncontrolled resource consumption vulnerability in HAProxy could allow an authenticated remote attacker to crash the service by running a specially crafted malicious server in an OpenShift cluster....