Haproxy
9 known vulnerabilities
Top Products
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert()
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches
Frequently Asked Questions
How many CVEs affect Haproxy?
Haproxy has 9 CVE records in our database, including 0 critical and 2 high severity vulnerabilities.
What are the most severe Haproxy vulnerabilities?
Haproxy has 0 critical severity (CVSS 9.0+) and 2 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Haproxy vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Haproxy products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Haproxy Vulnerabilities
CyberStrike scans your infrastructure for Haproxy vulnerabilities and provides real-time remediation guidance.
Get Started