Vulnerabilidades en haproxy
7 resultadosAnálisis Vexday
HAProxy apresenta 2 vulnerabilidades catalogadas, sendo 1 crítica e ambas publicadas recentemente (últimos 90 dias), com fraqueza dominante em estouro de inteiro (CWE-190). Nenhuma das vulnerabilidades está sob exploração ativa conhecida no momento, reduzindo o risco imediato, mas a recência das divulgações demanda atenção à aplicação de patches.
CVE-2025-32464MEDIUMHAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling ofEPSS 0.7%CVE-2026-55204HIGHHAProxy - NULL Pointer Dereference in hpack_dht_insert FunctionEPSS 0.5%CVE-2026-26080LOWHAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALEPSS 0.4%CVE-2026-26081MEDIUMHAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also EPSS 0.4%CVE-2026-55203CRITICALHAProxy - Integer Overflow in FCGI Demux Record Length FieldEPSS 0.3%CVE-2026-33555MEDIUMAn issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announcEPSS 0.3%CVE-2025-59303MEDIUMHAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with EPSS 0.2%