HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Haproxy | Haproxy | 2.9.0 (including) | 2.9.10 (excluding) |
Haproxy | Haproxy | 3.0.0 (including) | 3.0.4 (excluding) |
Haproxy | Haproxy | 3.1-dev0 (including) | 3.1-dev0 (including) |
Haproxy | Haproxy | 3.1-dev1 (including) | 3.1-dev1 (including) |
Haproxy | Haproxy | 3.1-dev2 (including) | 3.1-dev2 (including) |
Haproxy | Haproxy | 3.1-dev3 (including) | 3.1-dev3 (including) |
Haproxy | Haproxy | 3.1-dev4 (including) | 3.1-dev4 (including) |
Haproxy | Haproxy | 3.1-dev5 (including) | 3.1-dev5 (including) |
Haproxy | Ubuntu | devel | * |
Haproxy | Ubuntu | upstream | * |