CVE Vulnerabilities

CVE-2024-45506

Published: Sep 04, 2024 | Modified: Mar 14, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

Affected Software

NameVendorStart VersionEnd Version
HaproxyHaproxy2.9.0 (including)2.9.10 (excluding)
HaproxyHaproxy3.0.0 (including)3.0.4 (excluding)
HaproxyHaproxy3.1-dev0 (including)3.1-dev0 (including)
HaproxyHaproxy3.1-dev1 (including)3.1-dev1 (including)
HaproxyHaproxy3.1-dev2 (including)3.1-dev2 (including)
HaproxyHaproxy3.1-dev3 (including)3.1-dev3 (including)
HaproxyHaproxy3.1-dev4 (including)3.1-dev4 (including)
HaproxyHaproxy3.1-dev5 (including)3.1-dev5 (including)
HaproxyUbuntudevel*
HaproxyUbuntuupstream*

References