HAProxy records
38 published records for vendor haproxy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 94.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')4
- CWE-125 Out-of-bounds Read3
- CWE-190 Integer Overflow or Wraparound2
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
38 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2020-11100No exploit | In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary byteshaproxy · haproxy · CWE-787 | High8.8 | — | 60.7% | Apr 2, 2020 |
51Plan | CVE-2019-14241No exploit | HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prothaproxy · haproxy · CWE-835 | High7.5 | — | 70.2% | Jul 23, 2019 |
47Plan | CVE-2021-40346Proof of concept | An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, ahaproxy · haproxy · CWE-190 | High7.5 | — | 57.9% | Sep 8, 2021 |
43Plan | CVE-2016-5360No exploit | HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memorhaproxy · haproxy · CWE-119 | High7.5 | — | 42.8% | Jun 30, 2016 |
40Plan | CVE-2019-19330No exploit | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, AShaproxy · haproxy · CWE-74 | Critical9.8 | — | 4.0% | Nov 27, 2019 |
38Monitor | CVE-2023-25725Proof of concept | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuhaproxy · haproxy · CWE-444 | Critical9.1 | — | 5.4% | Feb 14, 2023 |
36Monitor | CVE-2026-55203No exploit | HAProxy - Integer Overflow in FCGI Demux Record Length Fieldhaproxy · haproxy · CWE-190 | Critical9.0 | — | 0.6% | Jun 18, 2026 |
35Monitor | CVE-2022-0711No exploit | A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header.haproxy · haproxy · CWE-835 | High7.5 | — | 16.6% | Mar 2, 2022 |
34Monitor | CVE-2026-55204No exploit | HAProxy - NULL Pointer Dereference in hpack_dht_insert Functionhaproxy · haproxy · CWE-476 | High8.7 | — | 0.5% | Jun 18, 2026 |
33Monitor | CVE-2019-18277No exploit | A flaw was found in HAProxy before 2.0.6.haproxy · haproxy · CWE-444 | High7.5 | — | 10.0% | Oct 23, 2019 |
32Monitor | CVE-2018-10184No exploit | An issue was discovered in HAProxy before 1.8.8.haproxy · haproxy · CWE-119 | High7.5 | — | 8.3% | May 9, 2018 |
32Monitor | CVE-2018-20103No exploit | An issue was discovered in dns.c in HAProxy through 1.8.14.haproxy · haproxy · CWE-835 | High7.5 | — | 6.6% | Dec 12, 2018 |
32Monitor | CVE-2023-45539Proof of concept | HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unsphaproxy · haproxy · CWE-116 | High8.2 | — | 1.5% | Nov 28, 2023 |
31Monitor | CVE-2018-20615No exploit | An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crahaproxy · haproxy · CWE-125 | High7.5 | — | 4.5% | Mar 21, 2019 |
31Monitor | CVE-2019-14243No exploit | headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, haproxy · proxyprotocol · CWE-20 | High7.5 | — | 4.3% | Jul 23, 2019 |
31Monitor | CVE-2018-20102No exploit | An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14.haproxy · haproxy · CWE-125 | High7.5 | — | 4.2% | Dec 12, 2018 |
31Monitor | CVE-2018-14645No exploit | A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2.haproxy · haproxy · CWE-125 | High7.5 | — | 3.0% | Sep 21, 2018 |
31Monitor | CVE-2021-39242No exploit | An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.haproxy · haproxy · CWE-755 | High7.5 | — | 2.2% | Aug 17, 2021 |
31Monitor | CVE-2021-39240No exploit | An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.haproxy · haproxy | High7.5 | — | 2.2% | Aug 17, 2021 |
30Monitor | CVE-2023-25950Proof of concept | HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate ushaproxy · haproxy · CWE-444 | High7.3 | — | 3.0% | Apr 11, 2023 |
30Monitor | CVE-2024-45506No exploit | HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwardinhaproxy · haproxy · CWE-835 | High7.5 | — | 1.2% | Sep 4, 2024 |
30Monitor | CVE-2023-0836No exploit | An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.haproxy · haproxy · CWE-200 | High7.5 | — | 1.2% | Mar 29, 2023 |
30Monitor | CVE-2025-11230No exploit | Denial of service vulnerability in HAProxy mjson libraryhaproxy · aloha appliance · CWE-407 | High7.5 | — | 0.7% | Nov 19, 2025 |
29Monitor | CVE-2023-40225No exploit | HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, haproxy · haproxy · CWE-444 | High7.2 | — | 2.1% | Aug 10, 2023 |
27Monitor | CVE-2023-0056No exploit | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.haproxy · haproxy · CWE-400 | Medium6.5 | — | 1.8% | Mar 23, 2023 |
- CVE-2020-1110053Plan
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes
HighCVSS 8.8No exploitEPSS 61%haproxy · haproxyApr 2, 2020
- CVE-2019-1424151Plan
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot
HighCVSS 7.5No exploitEPSS 70%haproxy · haproxyJul 23, 2019
- CVE-2021-4034647Plan
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, a
HighCVSS 7.5Proof of conceptEPSS 58%haproxy · haproxySep 8, 2021
- CVE-2016-536043Plan
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memor
HighCVSS 7.5No exploitEPSS 43%haproxy · haproxyJun 30, 2016
- CVE-2019-1933040Plan
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, AS
CriticalCVSS 9.8No exploitEPSS 4%haproxy · haproxyNov 27, 2019
- CVE-2023-2572538Monitor
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smu
CriticalCVSS 9.1Proof of conceptEPSS 5%haproxy · haproxyFeb 14, 2023
- CVE-2026-5520336Monitor
HAProxy - Integer Overflow in FCGI Demux Record Length Field
CriticalCVSS 9.0No exploitEPSS 1%haproxy · haproxyJun 18, 2026
- CVE-2022-071135Monitor
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header.
HighCVSS 7.5No exploitEPSS 17%haproxy · haproxyMar 2, 2022
- CVE-2026-5520434Monitor
HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
HighCVSS 8.7No exploitEPSS 0%haproxy · haproxyJun 18, 2026
- CVE-2019-1827733Monitor
A flaw was found in HAProxy before 2.0.6.
HighCVSS 7.5No exploitEPSS 10%haproxy · haproxyOct 23, 2019
- CVE-2018-1018432Monitor
An issue was discovered in HAProxy before 1.8.8.
HighCVSS 7.5No exploitEPSS 8%haproxy · haproxyMay 9, 2018
- CVE-2018-2010332Monitor
An issue was discovered in dns.c in HAProxy through 1.8.14.
HighCVSS 7.5No exploitEPSS 7%haproxy · haproxyDec 12, 2018
- CVE-2023-4553932Monitor
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unsp
HighCVSS 8.2Proof of conceptEPSS 2%haproxy · haproxyNov 28, 2023
- CVE-2018-2061531Monitor
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a cra
HighCVSS 7.5No exploitEPSS 4%haproxy · haproxyMar 21, 2019
- CVE-2019-1424331Monitor
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy,
HighCVSS 7.5No exploitEPSS 4%haproxy · proxyprotocolJul 23, 2019
- CVE-2018-2010231Monitor
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14.
HighCVSS 7.5No exploitEPSS 4%haproxy · haproxyDec 12, 2018
- CVE-2018-1464531Monitor
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2.
HighCVSS 7.5No exploitEPSS 3%haproxy · haproxySep 21, 2018
- CVE-2021-3924231Monitor
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.
HighCVSS 7.5No exploitEPSS 2%haproxy · haproxyAug 17, 2021
- CVE-2021-3924031Monitor
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.
HighCVSS 7.5No exploitEPSS 2%haproxy · haproxyAug 17, 2021
- CVE-2023-2595030Monitor
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate us
HighCVSS 7.3Proof of conceptEPSS 3%haproxy · haproxyApr 11, 2023
- CVE-2024-4550630Monitor
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwardin
HighCVSS 7.5No exploitEPSS 1%haproxy · haproxySep 4, 2024
- CVE-2023-083630Monitor
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.
HighCVSS 7.5No exploitEPSS 1%haproxy · haproxyMar 29, 2023
- CVE-2025-1123030Monitor
Denial of service vulnerability in HAProxy mjson library
HighCVSS 7.5No exploitEPSS 1%haproxy · aloha applianceNov 19, 2025
- CVE-2023-4022529Monitor
HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10,
HighCVSS 7.2No exploitEPSS 2%haproxy · haproxyAug 10, 2023
- CVE-2023-005627Monitor
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.
MediumCVSS 6.5No exploitEPSS 2%haproxy · haproxyMar 23, 2023