haproxy kayıtları
haproxy üreticisine ait 38 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %94,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')4
- CWE-125 Out-of-bounds Read3
- CWE-190 Integer Overflow or Wraparound2
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
38 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2020-11100İstismar yok | In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary byteshaproxy · haproxy · CWE-787 | Yüksek8,8 | — | %60,7 | 2 Nis 2020 |
51Planlayın | CVE-2019-14241İstismar yok | HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prothaproxy · haproxy · CWE-835 | Yüksek7,5 | — | %70,2 | 23 Tem 2019 |
47Planlayın | CVE-2021-40346Kavram kanıtı | An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, ahaproxy · haproxy · CWE-190 | Yüksek7,5 | — | %57,9 | 8 Eyl 2021 |
43Planlayın | CVE-2016-5360İstismar yok | HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memorhaproxy · haproxy · CWE-119 | Yüksek7,5 | — | %42,8 | 30 Haz 2016 |
40Planlayın | CVE-2019-19330İstismar yok | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, AShaproxy · haproxy · CWE-74 | Kritik9,8 | — | %4,0 | 27 Kas 2019 |
38İzleyin | CVE-2023-25725Kavram kanıtı | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuhaproxy · haproxy · CWE-444 | Kritik9,1 | — | %5,4 | 14 Şub 2023 |
36İzleyin | CVE-2026-55203İstismar yok | HAProxy - Integer Overflow in FCGI Demux Record Length Fieldhaproxy · haproxy · CWE-190 | Kritik9,0 | — | %0,6 | 18 Haz 2026 |
35İzleyin | CVE-2022-0711İstismar yok | A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header.haproxy · haproxy · CWE-835 | Yüksek7,5 | — | %16,6 | 2 Mar 2022 |
34İzleyin | CVE-2026-55204İstismar yok | HAProxy - NULL Pointer Dereference in hpack_dht_insert Functionhaproxy · haproxy · CWE-476 | Yüksek8,7 | — | %0,5 | 18 Haz 2026 |
33İzleyin | CVE-2019-18277İstismar yok | A flaw was found in HAProxy before 2.0.6.haproxy · haproxy · CWE-444 | Yüksek7,5 | — | %10,0 | 23 Eki 2019 |
32İzleyin | CVE-2018-10184İstismar yok | An issue was discovered in HAProxy before 1.8.8.haproxy · haproxy · CWE-119 | Yüksek7,5 | — | %8,3 | 9 May 2018 |
32İzleyin | CVE-2018-20103İstismar yok | An issue was discovered in dns.c in HAProxy through 1.8.14.haproxy · haproxy · CWE-835 | Yüksek7,5 | — | %6,6 | 12 Ara 2018 |
32İzleyin | CVE-2023-45539Kavram kanıtı | HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unsphaproxy · haproxy · CWE-116 | Yüksek8,2 | — | %1,5 | 28 Kas 2023 |
31İzleyin | CVE-2018-20615İstismar yok | An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crahaproxy · haproxy · CWE-125 | Yüksek7,5 | — | %4,5 | 21 Mar 2019 |
31İzleyin | CVE-2019-14243İstismar yok | headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, haproxy · proxyprotocol · CWE-20 | Yüksek7,5 | — | %4,3 | 23 Tem 2019 |
31İzleyin | CVE-2018-20102İstismar yok | An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14.haproxy · haproxy · CWE-125 | Yüksek7,5 | — | %4,2 | 12 Ara 2018 |
31İzleyin | CVE-2018-14645İstismar yok | A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2.haproxy · haproxy · CWE-125 | Yüksek7,5 | — | %3,0 | 21 Eyl 2018 |
31İzleyin | CVE-2021-39242İstismar yok | An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.haproxy · haproxy · CWE-755 | Yüksek7,5 | — | %2,2 | 17 Ağu 2021 |
31İzleyin | CVE-2021-39240İstismar yok | An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.haproxy · haproxy | Yüksek7,5 | — | %2,2 | 17 Ağu 2021 |
30İzleyin | CVE-2023-25950Kavram kanıtı | HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate ushaproxy · haproxy · CWE-444 | Yüksek7,3 | — | %3,0 | 11 Nis 2023 |
30İzleyin | CVE-2024-45506İstismar yok | HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwardinhaproxy · haproxy · CWE-835 | Yüksek7,5 | — | %1,2 | 4 Eyl 2024 |
30İzleyin | CVE-2023-0836İstismar yok | An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.haproxy · haproxy · CWE-200 | Yüksek7,5 | — | %1,2 | 29 Mar 2023 |
30İzleyin | CVE-2025-11230İstismar yok | Denial of service vulnerability in HAProxy mjson libraryhaproxy · aloha appliance · CWE-407 | Yüksek7,5 | — | %0,7 | 19 Kas 2025 |
29İzleyin | CVE-2023-40225İstismar yok | HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, haproxy · haproxy · CWE-444 | Yüksek7,2 | — | %2,1 | 10 Ağu 2023 |
27İzleyin | CVE-2023-0056İstismar yok | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.haproxy · haproxy · CWE-400 | Orta6,5 | — | %1,8 | 23 Mar 2023 |
- CVE-2020-1110053Planlayın
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes
YüksekCVSS 8,8İstismar yokEPSS %61haproxy · haproxy2 Nis 2020
- CVE-2019-1424151Planlayın
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in prot
YüksekCVSS 7,5İstismar yokEPSS %70haproxy · haproxy23 Tem 2019
- CVE-2021-4034647Planlayın
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, a
YüksekCVSS 7,5Kavram kanıtıEPSS %58haproxy · haproxy8 Eyl 2021
- CVE-2016-536043Planlayın
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memor
YüksekCVSS 7,5İstismar yokEPSS %43haproxy · haproxy30 Haz 2016
- CVE-2019-1933040Planlayın
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, AS
KritikCVSS 9,8İstismar yokEPSS %4haproxy · haproxy27 Kas 2019
- CVE-2023-2572538İzleyin
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smu
KritikCVSS 9,1Kavram kanıtıEPSS %5haproxy · haproxy14 Şub 2023
- CVE-2026-5520336İzleyin
HAProxy - Integer Overflow in FCGI Demux Record Length Field
KritikCVSS 9,0İstismar yokEPSS %1haproxy · haproxy18 Haz 2026
- CVE-2022-071135İzleyin
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header.
YüksekCVSS 7,5İstismar yokEPSS %17haproxy · haproxy2 Mar 2022
- CVE-2026-5520434İzleyin
HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
YüksekCVSS 8,7İstismar yokEPSS %0haproxy · haproxy18 Haz 2026
- CVE-2019-1827733İzleyin
A flaw was found in HAProxy before 2.0.6.
YüksekCVSS 7,5İstismar yokEPSS %10haproxy · haproxy23 Eki 2019
- CVE-2018-1018432İzleyin
An issue was discovered in HAProxy before 1.8.8.
YüksekCVSS 7,5İstismar yokEPSS %8haproxy · haproxy9 May 2018
- CVE-2018-2010332İzleyin
An issue was discovered in dns.c in HAProxy through 1.8.14.
YüksekCVSS 7,5İstismar yokEPSS %7haproxy · haproxy12 Ara 2018
- CVE-2023-4553932İzleyin
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unsp
YüksekCVSS 8,2Kavram kanıtıEPSS %2haproxy · haproxy28 Kas 2023
- CVE-2018-2061531İzleyin
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a cra
YüksekCVSS 7,5İstismar yokEPSS %4haproxy · haproxy21 Mar 2019
- CVE-2019-1424331İzleyin
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy,
YüksekCVSS 7,5İstismar yokEPSS %4haproxy · proxyprotocol23 Tem 2019
- CVE-2018-2010231İzleyin
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14.
YüksekCVSS 7,5İstismar yokEPSS %4haproxy · haproxy12 Ara 2018
- CVE-2018-1464531İzleyin
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2.
YüksekCVSS 7,5İstismar yokEPSS %3haproxy · haproxy21 Eyl 2018
- CVE-2021-3924231İzleyin
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.
YüksekCVSS 7,5İstismar yokEPSS %2haproxy · haproxy17 Ağu 2021
- CVE-2021-3924031İzleyin
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3.
YüksekCVSS 7,5İstismar yokEPSS %2haproxy · haproxy17 Ağu 2021
- CVE-2023-2595030İzleyin
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate us
YüksekCVSS 7,3Kavram kanıtıEPSS %3haproxy · haproxy11 Nis 2023
- CVE-2024-4550630İzleyin
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwardin
YüksekCVSS 7,5İstismar yokEPSS %1haproxy · haproxy4 Eyl 2024
- CVE-2023-083630İzleyin
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.
YüksekCVSS 7,5İstismar yokEPSS %1haproxy · haproxy29 Mar 2023
- CVE-2025-1123030İzleyin
Denial of service vulnerability in HAProxy mjson library
YüksekCVSS 7,5İstismar yokEPSS %1haproxy · aloha appliance19 Kas 2025
- CVE-2023-4022529İzleyin
HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10,
YüksekCVSS 7,2İstismar yokEPSS %2haproxy · haproxy10 Ağu 2023
- CVE-2023-005627İzleyin
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.
OrtaCVSS 6,5İstismar yokEPSS %2haproxy · haproxy23 Mar 2023