<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – HAProxy (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/haproxy.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/haproxy-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – HAProxy (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-1784 – The Route OpenShift resource allows to define routes to make pods reachable at a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1784</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1784</strong></p>
  <p>The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39806 – Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39806</guid>
    <pubDate>Wed, 13 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39806</strong></p>
  <p>Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion.  'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-chunk line 0\r\n is followed immediately by the empty trailer line \r\n. RFC 9112 §7.1.2 permits zero or more trailer f…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33208 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33208</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33208</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into a shell command string that is subsequently executed on a remote managed server via SSH. An authenticated attacker can inject arbitrary shell metach…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33078 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33078</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33078</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through multiple function calls and ultimately interpolated into a SQL query string using Python string form…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33077 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33077</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33077</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33076 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33076</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33076</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing into scheduled tasks. Version 8.2.6.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33432 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33432</guid>
    <pubDate>Mon, 20 Apr 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33432</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the filter string without escaping LDAP special characters. An unauthenticated attacker can inject LDAP filter metacharacters int…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5501 – wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5501</guid>
    <pubDate>Fri, 10 Apr 2026 04:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5501</strong></p>
  <p>wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf certificate from a trusted CA (e.g. a free DV cert from Let's Encrypt) can forge a certificate for a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3547 – Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3547</guid>
    <pubDate>Thu, 19 Mar 2026 21:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3547</strong></p>
  <p>Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party com…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27811 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27811</guid>
    <pubDate>Wed, 18 Mar 2026 00:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27811</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability exists in the `/config/compare/<service>/<server_ip>/show` endpoint, allowed authenticated users to execute arbitrary system commands on the app host. The vulnerability exists in `app/modules/config/config.py` on line 362, where user input is directly…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27630 – TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27630</guid>
    <pubDate>Thu, 26 Feb 2026 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27630</strong></p>
  <p>TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack known as Slowloris. The server spawns a new OS thread for every incoming connection without enforcing a maximum concurrency limit or an appropriate request timeout. An unauthenticated remote attacker can exhaust server concurrency limits and memory b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22265 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22265</guid>
    <pubDate>Thu, 15 Jan 2026 17:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22265</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in app/modules/roxywi/logs.py line 87, where the grep parameter is used twice - once sanitized and once raw. This vulnerability is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11230 – Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11230</guid>
    <pubDate>Wed, 19 Nov 2025 10:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11230</strong></p>
  <p>Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6714 – MongoDB Server's mongos component can become unresponsive to new connections due...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6714</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6714</strong></p>
  <p>MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20 and MongoDB Server v8.0 prior to 8.0.9  Required Configuration:  This affects MongoDB sharded clusters when configured…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46728 – cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46728</guid>
    <pubDate>Tue, 06 May 2025 01:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46728</strong></p>
  <p>cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding: chunked` is used or when no `Content-Length` header is provided. A remote attacker can send a chunked request without the terminating zero-length chunk, causing uncontrolled memory allocation on the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45506 – HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45506</guid>
    <pubDate>Wed, 04 Sep 2024 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45506</strong></p>
  <p>HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43804 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43804</guid>
    <pubDate>Thu, 29 Aug 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43804</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied input is used without validation when constructing and executing an OS command. User supplied JSON POST data is parsed and…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37082 – When deploying Cloud Foundry together with the haproxy-boshrelease and using a n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37082</guid>
    <pubDate>Wed, 03 Jul 2024 06:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37082</strong></p>
  <p>When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications.   You are affected if you have route-services enabled in routing-release and have configured the haproxy-boshrelease property “ha_proxy.forwarded_client_cert” to “forward_only_if_route_s…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28101 – The Apollo Router is a graph router written in Rust to run a federated supergrap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28101</guid>
    <pubDate>Thu, 21 Mar 2024 02:52:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28101</strong></p>
  <p>The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes` configuration option after the entirety of the compressed payload is decompressed…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45539 – HAProxy before 2.8.2 accepts # as part of the URI component, which might allow r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45539</guid>
    <pubDate>Tue, 28 Nov 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45539</strong></p>
  <p>HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40225 – HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40225</guid>
    <pubDate>Thu, 10 Aug 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40225</strong></p>
  <p>HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25950 – HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25950</guid>
    <pubDate>Tue, 11 Apr 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25950</strong></p>
  <p>HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0836 – An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0836</guid>
    <pubDate>Wed, 29 Mar 2023 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0836</strong></p>
  <p>An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25804 – Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25804</guid>
    <pubDate>Wed, 15 Mar 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25804</strong></p>
  <p>Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the `/tmp` folder using a payload `../../../../../tmp/test111_dev`. This issue has been fixed in version 6.3.5.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25803 – Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25803</guid>
    <pubDate>Mon, 13 Mar 2023 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25803</strong></p>
  <p>Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerability that allows the inclusion of server-side files. This issue is fixed in version 6.3.5.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-25802 – Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25802</guid>
    <pubDate>Mon, 13 Mar 2023 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-25802</strong></p>
  <p>Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a patch for this issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-25725 – HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25725</guid>
    <pubDate>Tue, 14 Feb 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-25725</strong></p>
  <p>HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, t…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31161 – Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31161</guid>
    <pubDate>Fri, 15 Jul 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31161</strong></p>
  <p>Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31137 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31137</guid>
    <pubDate>Fri, 08 Jul 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31137</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are a…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31126 – Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31126</guid>
    <pubDate>Wed, 06 Jul 2022 18:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31126</strong></p>
  <p>Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31125 – Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31125</guid>
    <pubDate>Wed, 06 Jul 2022 18:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31125</strong></p>
  <p>Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4047 – The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4047</guid>
    <pubDate>Mon, 11 Apr 2022 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4047</strong></p>
  <p>The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0711 – A flaw was found in the way HAProxy processed HTTP responses containing the "Set...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0711</guid>
    <pubDate>Wed, 02 Mar 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0711</strong></p>
  <p>A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40346 – An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40346</guid>
    <pubDate>Wed, 08 Sep 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40346</strong></p>
  <p>An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39242 – An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39242</guid>
    <pubDate>Tue, 17 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39242</strong></p>
  <p>An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39240 – An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39240</guid>
    <pubDate>Tue, 17 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39240</strong></p>
  <p>An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field (as observed on a target HTTP/2 server) might differ from what the routing rules were intended to achieve.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35195 – The official haproxy docker images before 1.8.18-alpine (Alpine specific) contai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35195</guid>
    <pubDate>Thu, 17 Dec 2020 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35195</strong></p>
  <p>The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11100 – In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11100</guid>
    <pubDate>Thu, 02 Apr 2020 15:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11100</strong></p>
  <p>In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19330 – The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demons...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19330</guid>
    <pubDate>Wed, 27 Nov 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19330</strong></p>
  <p>The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18277 – A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18277</guid>
    <pubDate>Wed, 23 Oct 2019 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18277</strong></p>
  <p>A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14243 – headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the masterc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14243</guid>
    <pubDate>Tue, 23 Jul 2019 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14243</strong></p>
  <p>headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webserver panic and daemon crash) via a crafted HAProxy PROXY v2 request with truncated source/destination address data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14241 – HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14241</guid>
    <pubDate>Tue, 23 Jul 2019 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14241</strong></p>
  <p>HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-20615 – An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20615</guid>
    <pubDate>Thu, 21 Mar 2019 16:00:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-20615</strong></p>
  <p>An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-20103 – An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20103</guid>
    <pubDate>Wed, 12 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-20103</strong></p>
  <p>An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-20102 – An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20102</guid>
    <pubDate>Wed, 12 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-20102</strong></p>
  <p>An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14645 – A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14645</guid>
    <pubDate>Fri, 21 Sep 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14645</strong></p>
  <p>A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10184 – An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10184</guid>
    <pubDate>Wed, 09 May 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10184</strong></p>
  <p>An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked against the bufsize. The max_frame_size only applies to outgoing traffic and not to incoming, so if a large enough frame size is advertised in the SETTINGS frame, a wrapped frame will be defragmented into a temporary allocated buffer where the secon…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5360 – HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5360</guid>
    <pubDate>Thu, 30 Jun 2016 17:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5360</strong></p>
  <p>HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5360">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
