CVE Vulnerabilities

CVE-2025-11230

Inefficient Algorithmic Complexity

Published: Nov 19, 2025 | Modified: Nov 19, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

Weakness

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat haproxy-0:3.0.5-4.el10_1.1 *
Red Hat Enterprise Linux 10.0 Extended Update Support RedHat haproxy-0:3.0.5-4.el10_0.1 *
Red Hat Enterprise Linux 9 RedHat haproxy-0:2.8.14-1.el9_7.1 *
Red Hat Enterprise Linux 9.6 Extended Update Support RedHat haproxy-0:2.4.22-4.el9_6.1 *
Haproxy Ubuntu devel *
Haproxy Ubuntu jammy *
Haproxy Ubuntu noble *
Haproxy Ubuntu plucky *

References