The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade haproxy | Dec 1, 2016 | Jul 6, 2015 |
| Debian | — | Upgrade haproxy | Jul 30, 2024 | Jul 6, 2015 |
| Freebsd | — | Upgrade haproxy | Dec 10, 2025 | Jul 7, 2015 |
| Oracle_linux | — | Upgrade haproxy | Oct 16, 2024 | Jul 6, 2015 |
| Redhat Openshift | — | Upgrade openshift-origin-cartridge-haproxyUpgrade rhcUpgrade rubygem-openshift-origin-commonUpgrade rubygem-openshift-origin-routing-daemonUpgrade openshift-origin-cartridge-jbossewsUpgrade openshift-enterprise-upgradeUpgrade openshift-origin-node-utilUpgrade haproxy15sideUpgrade openshift-origin-cartridge-pythonUpgrade openshift-origin-cartridge-jbosseapUpgrade openshift-origin-broker-utilUpgrade rubygem-openshift-origin-controllerUpgrade rubygem-openshift-origin-node | Oct 8, 2019 | Jul 7, 2015 |
| Suse | — | Upgrade haproxy | Dec 18, 2015 | Jul 6, 2015 |
| Ubuntu | — | Upgrade haproxy | Nov 8, 2024 | Jul 6, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub