Записи HAProxy
38 опубликованных записей вендора haproxy.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 94,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')4
- CWE-125 Out-of-bounds Read3
- CWE-190 Integer Overflow or Wraparound2
- CWE-20 Improper Input Validation2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
38 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2020-11100Эксплойта нет | In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary byteshaproxy · haproxy · CWE-787 | Высокая8,8 | — | 60,7 % | 2 апр. 2020 г. |
51В плане | CVE-2019-14241Эксплойта нет | HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prothaproxy · haproxy · CWE-835 | Высокая7,5 | — | 70,2 % | 23 июл. 2019 г. |
47В плане | CVE-2021-40346Proof of concept | An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, ahaproxy · haproxy · CWE-190 | Высокая7,5 | — | 57,9 % | 8 сент. 2021 г. |
43В плане | CVE-2016-5360Эксплойта нет | HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memorhaproxy · haproxy · CWE-119 | Высокая7,5 | — | 42,8 % | 30 июн. 2016 г. |
40В плане | CVE-2019-19330Эксплойта нет | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, AShaproxy · haproxy · CWE-74 | Критическая9,8 | — | 4,0 % | 27 нояб. 2019 г. |
38Наблюдать | CVE-2023-25725Proof of concept | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuhaproxy · haproxy · CWE-444 | Критическая9,1 | — | 5,4 % | 14 февр. 2023 г. |
36Наблюдать | CVE-2026-55203Эксплойта нет | HAProxy - Integer Overflow in FCGI Demux Record Length Fieldhaproxy · haproxy · CWE-190 | Критическая9,0 | — | 0,6 % | 18 июн. 2026 г. |
35Наблюдать | CVE-2022-0711Эксплойта нет | A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header.haproxy · haproxy · CWE-835 | Высокая7,5 | — | 16,6 % | 2 мар. 2022 г. |
34Наблюдать | CVE-2026-55204Эксплойта нет | HAProxy - NULL Pointer Dereference in hpack_dht_insert Functionhaproxy · haproxy · CWE-476 | Высокая8,7 | — | 0,5 % | 18 июн. 2026 г. |
33Наблюдать | CVE-2019-18277Эксплойта нет | A flaw was found in HAProxy before 2.0.6.haproxy · haproxy · CWE-444 | Высокая7,5 | — | 10,0 % | 23 окт. 2019 г. |
32Наблюдать | CVE-2018-10184Эксплойта нет | An issue was discovered in HAProxy before 1.8.8.haproxy · haproxy · CWE-119 | Высокая7,5 | — | 8,3 % | 9 мая 2018 г. |
32Наблюдать | CVE-2018-20103Эксплойта нет | An issue was discovered in dns.c in HAProxy through 1.8.14.haproxy · haproxy · CWE-835 | Высокая7,5 | — | 6,6 % | 12 дек. 2018 г. |
32Наблюдать | CVE-2023-45539Proof of concept | HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unsphaproxy · haproxy · CWE-116 | Высокая8,2 | — | 1,5 % | 28 нояб. 2023 г. |
31Наблюдать | CVE-2018-20615Эксплойта нет | An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crahaproxy · haproxy · CWE-125 | Высокая7,5 | — | 4,5 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2019-14243Эксплойта нет | headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, haproxy · proxyprotocol · CWE-20 | Высокая7,5 | — | 4,3 % | 23 июл. 2019 г. |
31Наблюдать | CVE-2018-20102Эксплойта нет | An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14.haproxy · haproxy · CWE-125 | Высокая7,5 | — | 4,2 % | 12 дек. 2018 г. |
31Наблюдать | CVE-2018-14645Эксплойта нет | A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2.haproxy · haproxy · CWE-125 | Высокая7,5 | — | 3,0 % | 21 сент. 2018 г. |
31Наблюдать | CVE-2021-39242Эксплойта нет | An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.haproxy · haproxy · CWE-755 | Высокая7,5 | — | 2,2 % | 17 авг. 2021 г. |
31Наблюдать | CVE-2021-39240Эксплойта нет | An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.haproxy · haproxy | Высокая7,5 | — | 2,2 % | 17 авг. 2021 г. |
30Наблюдать | CVE-2023-25950Proof of concept | HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate ushaproxy · haproxy · CWE-444 | Высокая7,3 | — | 3,0 % | 11 апр. 2023 г. |
30Наблюдать | CVE-2024-45506Эксплойта нет | HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwardinhaproxy · haproxy · CWE-835 | Высокая7,5 | — | 1,2 % | 4 сент. 2024 г. |
30Наблюдать | CVE-2023-0836Эксплойта нет | An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.haproxy · haproxy · CWE-200 | Высокая7,5 | — | 1,2 % | 29 мар. 2023 г. |
30Наблюдать | CVE-2025-11230Эксплойта нет | Denial of service vulnerability in HAProxy mjson libraryhaproxy · aloha appliance · CWE-407 | Высокая7,5 | — | 0,7 % | 19 нояб. 2025 г. |
29Наблюдать | CVE-2023-40225Эксплойта нет | HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, haproxy · haproxy · CWE-444 | Высокая7,2 | — | 2,1 % | 10 авг. 2023 г. |
27Наблюдать | CVE-2023-0056Эксплойта нет | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.haproxy · haproxy · CWE-400 | Средняя6,5 | — | 1,8 % | 23 мар. 2023 г. |
- CVE-2020-1110053В плане
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes
ВысокаяCVSS 8,8Эксплойта нетEPSS 61 %haproxy · haproxy2 апр. 2020 г.
- CVE-2019-1424151В плане
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot
ВысокаяCVSS 7,5Эксплойта нетEPSS 70 %haproxy · haproxy23 июл. 2019 г.
- CVE-2021-4034647В плане
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, a
ВысокаяCVSS 7,5Proof of conceptEPSS 58 %haproxy · haproxy8 сент. 2021 г.
- CVE-2016-536043В плане
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memor
ВысокаяCVSS 7,5Эксплойта нетEPSS 43 %haproxy · haproxy30 июн. 2016 г.
- CVE-2019-1933040В плане
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, AS
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %haproxy · haproxy27 нояб. 2019 г.
- CVE-2023-2572538Наблюдать
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smu
КритическаяCVSS 9,1Proof of conceptEPSS 5 %haproxy · haproxy14 февр. 2023 г.
- CVE-2026-5520336Наблюдать
HAProxy - Integer Overflow in FCGI Demux Record Length Field
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %haproxy · haproxy18 июн. 2026 г.
- CVE-2022-071135Наблюдать
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header.
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %haproxy · haproxy2 мар. 2022 г.
- CVE-2026-5520434Наблюдать
HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %haproxy · haproxy18 июн. 2026 г.
- CVE-2019-1827733Наблюдать
A flaw was found in HAProxy before 2.0.6.
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %haproxy · haproxy23 окт. 2019 г.
- CVE-2018-1018432Наблюдать
An issue was discovered in HAProxy before 1.8.8.
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %haproxy · haproxy9 мая 2018 г.
- CVE-2018-2010332Наблюдать
An issue was discovered in dns.c in HAProxy through 1.8.14.
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %haproxy · haproxy12 дек. 2018 г.
- CVE-2023-4553932Наблюдать
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unsp
ВысокаяCVSS 8,2Proof of conceptEPSS 2 %haproxy · haproxy28 нояб. 2023 г.
- CVE-2018-2061531Наблюдать
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a cra
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %haproxy · haproxy21 мар. 2019 г.
- CVE-2019-1424331Наблюдать
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy,
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %haproxy · proxyprotocol23 июл. 2019 г.
- CVE-2018-2010231Наблюдать
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %haproxy · haproxy12 дек. 2018 г.
- CVE-2018-1464531Наблюдать
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %haproxy · haproxy21 сент. 2018 г.
- CVE-2021-3924231Наблюдать
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %haproxy · haproxy17 авг. 2021 г.
- CVE-2021-3924031Наблюдать
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %haproxy · haproxy17 авг. 2021 г.
- CVE-2023-2595030Наблюдать
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate us
ВысокаяCVSS 7,3Proof of conceptEPSS 3 %haproxy · haproxy11 апр. 2023 г.
- CVE-2024-4550630Наблюдать
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwardin
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %haproxy · haproxy4 сент. 2024 г.
- CVE-2023-083630Наблюдать
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %haproxy · haproxy29 мар. 2023 г.
- CVE-2025-1123030Наблюдать
Denial of service vulnerability in HAProxy mjson library
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %haproxy · aloha appliance19 нояб. 2025 г.
- CVE-2023-4022529Наблюдать
HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10,
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %haproxy · haproxy10 авг. 2023 г.
- CVE-2023-005627Наблюдать
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %haproxy · haproxy23 мар. 2023 г.