Debian Haproxy vulnerabilities
35 known vulnerabilities affecting debian/haproxy.
Total CVEs
35
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH19MEDIUM11LOW3
Vulnerabilities
Page 2 of 2
CVE-2018-20615P3HIGHCVSS 7.5fixed in haproxy 1.8.16-2 (bookworm)2018
CVE-2018-20615 [HIGH] CVE-2018-20615: haproxy - An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAP...
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
Scope: local
bookworm:
debian
CVE-2013-1912P3MEDIUMCVSS 5.1fixed in haproxy 1.4.23-1 (bookworm)2013
CVE-2013-1912 [MEDIUM] CVE-2013-1912: haproxy - Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, whe...
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request re
debian
CVE-2023-0056P3MEDIUMCVSS 6.5fixed in haproxy 2.6.8-1 (bookworm)2023
CVE-2023-0056 [MEDIUM] CVE-2023-0056: haproxy - An uncontrolled resource consumption vulnerability was discovered in HAProxy whi...
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Scope: local
bookworm: resolved (fixed in 2.6.8-1)
bullseye: resolved (fixed in 2.2.9-2+deb11u4)
debian
CVE-2018-14645P3HIGHCVSS 7.5fixed in haproxy 1.8.13-2 (bookworm)2018
CVE-2018-14645 [HIGH] CVE-2018-14645: haproxy - A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is us...
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.13-2)
bullseye: resolved (fixed in 1.8.13-2)
forky: resolved (fixed in 1.8.13-2)
sid: resolved (fixed in 1.8.13-2)
trixie: reso
debian
CVE-2018-11469P4MEDIUMCVSS 5.9fixed in haproxy 1.8.9-2 (bookworm)2018
CVE-2018-11469 [MEDIUM] CVE-2018-11469: haproxy - Incorrect caching of responses to requests including an Authorization header in ...
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.
Scope: local
bookworm: resolved (fixed in 1.8.9-2)
bullseye: resolved (fixed in
debian
CVE-2025-32464P3MEDIUMCVSS 6.8fixed in haproxy 2.6.12-1+deb12u2 (bookworm)2025
CVE-2025-32464 [MEDIUM] CVE-2025-32464: haproxy - HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv...
HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.
Scope: local
bookworm: resolved (fixed in 2.6.12-1+deb12u2)
bullseye: resolved (fixed in 2.2.9-2+deb11u7)
forky: resolved (fixed in 3.0.10-1)
sid: resolved (fixed
debian
CVE-2012-2942P4MEDIUMCVSS 5.1fixed in haproxy 1.4.23-1 (bookworm)2012
CVE-2012-2942 [MEDIUM] CVE-2012-2942: haproxy - Buffer overflow in the trash buffer in the header capture functionality in HAPro...
Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater than the default and header rewriting is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.4.23-1)
bul
debian
CVE-2021-39241P4MEDIUMCVSS 5.3fixed in haproxy 2.2.16-1 (bookworm)2021
CVE-2021-39241 [MEDIUM] CVE-2021-39241: haproxy - An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 bef...
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" example.
Sco
debian
CVE-2024-53008P4MEDIUMCVSS 5.3fixed in haproxy 2.9.10-1 (forky)2024
CVE-2024-53008 [MEDIUM] CVE-2024-53008: haproxy - Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling')...
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
Scope: local
bookworm: open
bullseye: resolved
forky: resolv
debian
CVE-2024-49214P4MEDIUMCVSS 5.3fixed in haproxy 2.9.11-1 (forky)2024
CVE-2024-49214 [MEDIUM] CVE-2024-49214: haproxy - QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9....
QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 2.9.11-1)
sid: resolved (fixed in 2.9.11-1)
trixie: resolved (fixed in 2.9.11-1)
debian
CVE-2015-3281P4MEDIUMCVSS 5.0fixed in haproxy 1.5.14-1 (bookworm)2015
CVE-2015-3281 [MEDIUM] CVE-2015-3281: haproxy - The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does...
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
Scope: local
bookworm: resolved (fixed in 1.5.14-1)
bullseye: resolved (fixed i
debian
CVE-2014-6269P4MEDIUMCVSS 5.0fixed in haproxy 1.5.4-1 (bookworm)2014
CVE-2014-6269 [MEDIUM] CVE-2014-6269: haproxy - Multiple integer overflows in the http_request_forward_body function in proto_ht...
Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 1.5.4-1)
bullseye: resolved (fixed in 1.5.4-1)
forky: resol
debian
CVE-2026-26081P4LOWfixed in haproxy 3.2.11-2 (forky)2026
CVE-2026-26081 [LOW] CVE-2026-26081: haproxy
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 3.2.11-2)
sid: resolved (fixed in 3.2.11-2)
trixie: resolved (fixed in 3.0.11-1+deb13u2)
debian
CVE-2013-2175P4MEDIUMCVSS 5.0fixed in haproxy 1.4.24-1 (bookworm)2013
CVE-2013-2175 [MEDIUM] CVE-2013-2175: haproxy - HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_i...
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2026-26080P4LOWfixed in haproxy 3.2.11-2 (forky)2026
CVE-2026-26080 [LOW] CVE-2026-26080: haproxy
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 3.2.11-2)
sid: resolved (fixed in 3.2.11-2)
trixie: resolved
debian
← Previous2 / 2