CVE-2025-11230Inefficient Algorithmic Complexity in Technologies Haproxy Community Edition

Severity
7.5HIGHNVD
EPSS
0.4%
top 39.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19

Description

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages11 packages

debiandebian/haproxy< haproxy 2.6.12-1+deb12u3 (bookworm)
NVDhaproxy/haproxy2.4.02.4.30+5
NVDhaproxy/aloha_appliance14.5.014.5.33+3
NVDhaproxy/kubernetes_ingress_controller1.10.10-ee11.11.12-ee10+3

🔴Vulnerability Details

2
GHSA
GHSA-fc36-5gc3-jmhx: Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests2025-11-19
OSV
CVE-2025-11230: Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests2025-11-19

📋Vendor Advisories

4
Microsoft
Denial of service vulnerability in HAProxy mjson library2025-11-11
Ubuntu
HAProxy vulnerability2025-10-06
Red Hat
haproxy: denial of service vulnerability in HAProxy mjson library2025-10-03
Debian
CVE-2025-11230: haproxy - Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to ...2025

🕵️Threat Intelligence

2
Wiz
CVE-2026-26081 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-26080 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-11230 — Inefficient Algorithmic Complexity | cvebase