Vulnerabilidades em HAProxy
7 resultadosAnálise Vexday
HAProxy apresenta footprint reduzido com 5 CVEs registradas, sem incidentes de exploração ativa em campo (0 KEV) e nenhuma crítica de severidade. Contudo, 2 vulnerabilidades foram divulgadas nos últimos 90 dias, indicando risco recente, com padrão dominante em validação inadequada de entrada (CWE-130). O cenário sugere exposição controlada, mas demanda acompanhamento próximo das correções recentes.
CVE-2025-32464MEDIUMHAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling ofEPSS 0.7%CVE-2026-55204HIGHHAProxy - NULL Pointer Dereference in hpack_dht_insert FunctionEPSS 0.5%CVE-2026-26080LOWHAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALEPSS 0.4%CVE-2026-26081MEDIUMHAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also EPSS 0.4%CVE-2026-55203CRITICALHAProxy - Integer Overflow in FCGI Demux Record Length FieldEPSS 0.3%CVE-2026-33555MEDIUMAn issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announcEPSS 0.3%CVE-2025-59303MEDIUMHAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with EPSS 0.2%