The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade haproxy | Dec 1, 2016 | Jul 6, 2015 |
| Debian | — | Upgrade haproxy | Jul 30, 2024 | Jul 6, 2015 |
| Freebsd | — | Upgrade haproxy | Dec 10, 2025 | Jul 7, 2015 |
| Oracle_linux | — | Upgrade haproxy | Oct 16, 2024 | Jul 6, 2015 |
| Redhat Openshift | — | Upgrade rhcUpgrade rubygem-openshift-origin-nodeUpgrade rubygem-openshift-origin-routing-daemonUpgrade rubygem-openshift-origin-commonUpgrade openshift-origin-cartridge-haproxyUpgrade rubygem-openshift-origin-controllerUpgrade openshift-origin-node-utilUpgrade openshift-enterprise-upgradeUpgrade openshift-origin-cartridge-jbosseapUpgrade haproxy15sideUpgrade openshift-origin-broker-utilUpgrade openshift-origin-cartridge-pythonUpgrade openshift-origin-cartridge-jbossews | Oct 8, 2019 | Jul 7, 2015 |
| Suse | — | Upgrade haproxy | Dec 18, 2015 | Jul 6, 2015 |
| Ubuntu | — | Upgrade haproxy | Nov 8, 2024 | Jul 6, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub