Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade haproxy | Nov 20, 2025 | Nov 18, 2025 |
| Debian | — | Upgrade haproxy | Oct 6, 2025 | Oct 6, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade haproxy | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade haproxy | Jan 15, 2026 | Jan 13, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade haproxy | Feb 3, 2026 | Jan 13, 2026 |
| Oracle_linux | — | Upgrade haproxy | Nov 28, 2025 | Oct 3, 2025 |
| Redhat_linux | — | No solution existsUpgrade haproxy-debugsourceUpgrade haproxy-debuginfoUpgrade haproxy | Nov 19, 2025 | Oct 3, 2025 |
| Rocky_linux | — | Upgrade haproxy-debuginfoUpgrade haproxyUpgrade haproxy-debugsource | Feb 5, 2026 | Nov 21, 2025 |
| Suse | — | Upgrade haproxy | Dec 5, 2025 | Oct 13, 2025 |
| Ubuntu | — | Upgrade haproxy | Oct 7, 2025 | Oct 2, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub