Skip to content
Noroxi

HAProxy records

38 published records for vendor haproxy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
94.7%
Median publish → KEV
No record has entered KEV

All records

38 records
  • In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes

    HighCVSS 8.8No exploitEPSS 61%

    haproxy · haproxyApr 2, 2020

  • HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot

    HighCVSS 7.5No exploitEPSS 70%

    haproxy · haproxyJul 23, 2019

  • An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, a

    HighCVSS 7.5Proof of conceptEPSS 58%

    haproxy · haproxySep 8, 2021

  • HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memor

    HighCVSS 7.5No exploitEPSS 43%

    haproxy · haproxyJun 30, 2016

  • The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, AS

    CriticalCVSS 9.8No exploitEPSS 4%

    haproxy · haproxyNov 27, 2019

  • HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smu

    CriticalCVSS 9.1Proof of conceptEPSS 5%

    haproxy · haproxyFeb 14, 2023

  • HAProxy - Integer Overflow in FCGI Demux Record Length Field

    CriticalCVSS 9.0No exploitEPSS 1%

    haproxy · haproxyJun 18, 2026

  • CVE-2022-0711
    35Monitor

    A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header.

    HighCVSS 7.5No exploitEPSS 17%

    haproxy · haproxyMar 2, 2022

  • HAProxy - NULL Pointer Dereference in hpack_dht_insert Function

    HighCVSS 8.7No exploitEPSS 0%

    haproxy · haproxyJun 18, 2026

  • A flaw was found in HAProxy before 2.0.6.

    HighCVSS 7.5No exploitEPSS 10%

    haproxy · haproxyOct 23, 2019

  • An issue was discovered in HAProxy before 1.8.8.

    HighCVSS 7.5No exploitEPSS 8%

    haproxy · haproxyMay 9, 2018

  • An issue was discovered in dns.c in HAProxy through 1.8.14.

    HighCVSS 7.5No exploitEPSS 7%

    haproxy · haproxyDec 12, 2018

  • HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unsp

    HighCVSS 8.2Proof of conceptEPSS 2%

    haproxy · haproxyNov 28, 2023

  • An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a cra

    HighCVSS 7.5No exploitEPSS 4%

    haproxy · haproxyMar 21, 2019

  • headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy,

    HighCVSS 7.5No exploitEPSS 4%

    haproxy · proxyprotocolJul 23, 2019

  • An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14.

    HighCVSS 7.5No exploitEPSS 4%

    haproxy · haproxyDec 12, 2018

  • A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2.

    HighCVSS 7.5No exploitEPSS 3%

    haproxy · haproxySep 21, 2018

  • An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.

    HighCVSS 7.5No exploitEPSS 2%

    haproxy · haproxyAug 17, 2021

  • An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.

    HighCVSS 7.5No exploitEPSS 2%

    haproxy · haproxyAug 17, 2021

  • HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate us

    HighCVSS 7.3Proof of conceptEPSS 3%

    haproxy · haproxyApr 11, 2023

  • HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwardin

    HighCVSS 7.5No exploitEPSS 1%

    haproxy · haproxySep 4, 2024

  • CVE-2023-0836
    30Monitor

    An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.

    HighCVSS 7.5No exploitEPSS 1%

    haproxy · haproxyMar 29, 2023

  • Denial of service vulnerability in HAProxy mjson library

    HighCVSS 7.5No exploitEPSS 1%

    haproxy · aloha applianceNov 19, 2025

  • HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10,

    HighCVSS 7.2No exploitEPSS 2%

    haproxy · haproxyAug 10, 2023

  • CVE-2023-0056
    27Monitor

    An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.

    MediumCVSS 6.5No exploitEPSS 2%

    haproxy · haproxyMar 23, 2023