Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-45506


HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.


Published

2024-09-04T15:15:14.080

Last Modified

2025-03-14T20:15:13.870

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-835

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haproxy haproxy < 2.9.10 Yes
Application haproxy haproxy < 3.0.4 Yes
Application haproxy haproxy 3.1 Yes
Application haproxy haproxy 3.1 Yes
Application haproxy haproxy 3.1 Yes
Application haproxy haproxy 3.1 Yes
Application haproxy haproxy 3.1 Yes
Application haproxy haproxy 3.1 Yes

References