HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
2024-09-04T15:15:14.080
2025-03-14T20:15:13.870
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | haproxy | haproxy | < 2.9.10 | Yes |
| Application | haproxy | haproxy | < 3.0.4 | Yes |
| Application | haproxy | haproxy | 3.1 | Yes |
| Application | haproxy | haproxy | 3.1 | Yes |
| Application | haproxy | haproxy | 3.1 | Yes |
| Application | haproxy | haproxy | 3.1 | Yes |
| Application | haproxy | haproxy | 3.1 | Yes |
| Application | haproxy | haproxy | 3.1 | Yes |