Search CVE reports


Toggle filters

11 – 20 of 41 results


CVE-2023-44487

High priority

Some fixes available 33 of 46

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

14 affected packages

haproxy, tomcat10, tomcat9, trafficserver, h2o...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Not affected Not affected Not affected Fixed
tomcat10 Not affected Not in release Not in release Ignored
tomcat9 Not affected Fixed Fixed Fixed
trafficserver Not affected Fixed Fixed Not affected
h2o Not affected Fixed Fixed Fixed
tomcat8 Not in release Not in release Not in release Fixed
dotnet6 Not in release Fixed Not in release Not in release
dotnet7 Not in release Fixed Not in release Not in release
dotnet8 Fixed Not affected Not in release Not in release
nginx Not affected Not affected Not affected Not affected
nghttp2 Not affected Fixed Fixed Fixed
nodejs Not affected Fixed Fixed Fixed
netty Not affected Fixed Fixed Not affected
dnsdist Not affected Fixed Not affected Not affected
Show all 14 packages Show less packages

CVE-2023-40225

Medium priority
Fixed

HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Fixed Not affected
Show less packages

CVE-2023-25950

Medium priority
Not affected

HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Not affected Not affected Not affected
Show less packages

CVE-2023-0836

Medium priority
Fixed

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Not affected Not affected
Show less packages

CVE-2023-25725

Medium priority
Fixed

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-0056

Medium priority
Fixed

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Fixed Not affected
Show less packages

CVE-2022-0711

Medium priority
Fixed

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Not affected Fixed Not affected
Show less packages

CVE-2021-40346

Medium priority
Fixed

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Fixed Not affected
Show less packages

CVE-2021-39242

Medium priority
Fixed

An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Not affected Not affected
Show less packages

CVE-2021-39241

Medium priority
Fixed

An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server...

1 affected package

haproxy

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
haproxy Fixed Fixed Not affected
Show less packages