HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Haproxy | Haproxy | 2.9.0 (including) | 2.9.10 (excluding) | 
| Haproxy | Haproxy | 3.0.0 (including) | 3.0.4 (excluding) | 
| Haproxy | Haproxy | 3.1-dev0 (including) | 3.1-dev0 (including) | 
| Haproxy | Haproxy | 3.1-dev1 (including) | 3.1-dev1 (including) | 
| Haproxy | Haproxy | 3.1-dev2 (including) | 3.1-dev2 (including) | 
| Haproxy | Haproxy | 3.1-dev3 (including) | 3.1-dev3 (including) | 
| Haproxy | Haproxy | 3.1-dev4 (including) | 3.1-dev4 (including) | 
| Haproxy | Haproxy | 3.1-dev5 (including) | 3.1-dev5 (including) | 
| Haproxy | Ubuntu | devel | * | 
| Haproxy | Ubuntu | upstream | * |