CVE-2025-11230
published 2025-11-19CVE-2025-11230: Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.53%
41.5th percentile
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | haproxy | < haproxy 2.6.12-1+deb12u3 (bookworm) | haproxy 2.6.12-1+deb12u3 (bookworm) |
| haproxy | aloha_appliance | >= 14.5.0 < 14.5.33 | 14.5.33 |
| haproxy | aloha_appliance | >= 15.5.0 < 15.5.28 | 15.5.28 |
| haproxy | aloha_appliance | >= 16.5.0 < 16.5.19 | 16.5.19 |
| haproxy | aloha_appliance | >= 17.0.0 < 17.0.7 | 17.0.7 |
| haproxy | haproxy | >= 0 < 2.6.12-1+deb12u3 | 2.6.12-1+deb12u3 |
| haproxy | haproxy | >= 0 < 3.0.11-1+deb13u1 | 3.0.11-1+deb13u1 |
| haproxy | haproxy | >= 0 < 3.2.5-2 | 3.2.5-2 |
| haproxy | haproxy | >= 2.4.0 < 2.4.30 | 2.4.30 |
| haproxy | haproxy | >= 2.6.0 < 2.6.23 | 2.6.23 |
| haproxy | haproxy | >= 2.8.0 < 2.8.16 | 2.8.16 |
| haproxy | haproxy | >= 3.0.0 < 3.0.12 | 3.0.12 |
| haproxy | haproxy | >= 3.1.0 < 3.1.9 | 3.1.9 |
| haproxy | haproxy | >= 3.2.0 < 3.2.6 | 3.2.6 |
| haproxy | haproxy_enterprise | — | — |
| haproxy | haproxy_enterprise | — | — |
| haproxy | haproxy_enterprise | — | — |
| haproxy | haproxy_enterprise | — | — |
| haproxy | haproxy_enterprise | — | — |
| haproxy | kubernetes_ingress_controller | < 1.9.14-ee7 | 1.9.14-ee7 |
| haproxy | kubernetes_ingress_controller | < 3.1.12 | 3.1.12 |
| haproxy | kubernetes_ingress_controller | >= 1.10.10-ee1 < 1.11.12-ee10 | 1.11.12-ee10 |
| haproxy | kubernetes_ingress_controller | >= 3.0.0-ee1 < 3.0.15-ee4 | 3.0.15-ee4 |
| haproxy_technologies | haproxy_community_edition | >= 2.4.0 < 2.4.30 | 2.4.30 |
| haproxy_technologies | haproxy_community_edition | >= 2.6.0 < 2.6.23 | 2.6.23 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-11228
vendor_chrome·2026-06-02
CVE-2026-11228 [LOW] Stable Channel Update for Desktop: CVE-2026-11228
Stable Channel Update for Desktop
CVE-2026-11228: Incorrect security UI in File Input. Reported by Umar Farooq on 2025-10-23 [TBD][ 482713603 ] Low CVE-2026-11229: Insufficient policy enforcement in Enterprise
Reported by Povcfe of Tencent Security Xuanwu Lab on 2026-02-08 [N/A][ 493225428 ] Low CVE-2026-11230: Use after free in Extensions
Severity: low
Microsoft
Denial of service vulnerability in HAProxy mjson library
vendor_msrc·2025-11-11·CVSS 7.5
CVE-2025-11230 [HIGH] CWE-407 Denial of service vulnerability in HAProxy mjson library
Denial of service vulnerability in HAProxy mjson library
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Ubuntu
HAProxy vulnerability
vendor_ubuntu·2025-10-06
CVE-2025-11230 HAProxy vulnerability
Title: HAProxy vulnerability
Summary: HAProxy could be made to crash if it received specially crafted network
traffic.
Oula Kivalo discovered that HAProxy incorrectly handled parsing certain
json numbers. A remote attacker could possibly use this issue to cause
HAProxy to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
haproxy: denial of service vulnerability in HAProxy mjson library
vendor_redhat·2025-10-03·CVSS 7.5
CVE-2025-11230 [HIGH] CWE-407 haproxy: denial of service vulnerability in HAProxy mjson library
haproxy: denial of service vulnerability in HAProxy mjson library
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
A flaw was found in haproxy. A stemming from an inefficient algorithmic complexity issue within its bundled mjson parsing library. This vulnerability is triggered when haproxy is configured to analyze JSON content, such as with the json_query or jwt_payload_query function
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: haproxy (Red Hat Ceph Storage 5) - Affected
Package: hapro
Debian
CVE-2025-11230: haproxy - Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to ...
vendor_debian·2025·CVSS 7.5
CVE-2025-11230 [HIGH] CVE-2025-11230: haproxy - Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to ...
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
Scope: local
bookworm: resolved (fixed in 2.6.12-1+deb12u3)
bullseye: resolved
forky: resolved (fixed in 3.2.5-2)
sid: resolved (fixed in 3.2.5-2)
trixie: resolved (fixed in 3.0.11-1+deb13u1)
GHSA
GHSA-fc36-5gc3-jmhx: Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests
ghsa_unreviewed·2025-11-19
CVE-2025-11230 [HIGH] CWE-407 GHSA-fc36-5gc3-jmhx: Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
OSV
CVE-2025-11230: Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests
osv·2025-11-19·CVSS 7.5
CVE-2025-11230 [HIGH] CVE-2025-11230: Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-26081 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26081 [HIGH] CVE-2026-26081 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26081 :
HAProxy vulnerability analysis and mitigation
crash via INITIAL packet for the NEW_TOKEN format
Source : NVD
Published February 12, 2026
CNA Score N/A
Affected Technologies
HAProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
haproxy
Sources
NVD
Debian 13, 14 Has Fix Added at: Feb 12, 2026
Ubuntu 25.10 Severity MEDIUM Has Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related HAProxy vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV
Wiz
CVE-2026-26080 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26080 [HIGH] CVE-2026-26080 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26080 :
HAProxy vulnerability analysis and mitigation
crash in parsing frame type
Source : NVD
Published February 12, 2026
CNA Score N/A
Affected Technologies
HAProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
haproxy
Sources
NVD
Debian 14 Has Fix Added at: Feb 12, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related HAProxy vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2025-11230
HIGH
7.5
HAProxy
haproxy-2.4
No
Bugzilla
CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library
bugzilla·2025-11-06·CVSS 7.5
CVE-2025-11230 [HIGH] CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library
CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library
A flaw was found in haproxy. A stemming from an inefficient algorithmic complexity issue within its bundled mjson parsing library. This vulnerability is triggered when haproxy is configured to analyze JSON content, such as with the json_query or jwt_payload_query function
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:21691 https://access.redhat.com/errata/RHSA-2025:21691
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10.0 Extended Update Support
Via RHSA-2025:21692 https://access.redhat.com/errata/RHSA-2025:21692
---
This issue has been addressed in the following products:
Red Hat Enterprise Linu
Bugzilla
CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library [fedora-42]
bugzilla·2025-11-06·CVSS 7.5
CVE-2025-11230 [HIGH] CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library [fedora-42]
CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library [fedora-43]
bugzilla·2025-11-06·CVSS 7.5
CVE-2025-11230 [HIGH] CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library [fedora-43]
CVE-2025-11230 haproxy: denial of service vulnerability in HAProxy mjson library [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-2026-164a1e3151 (haproxy-3.0.23-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-164a1e3151
---
FEDORA-2026-164a1e3151 has been
2025-11-19
Published