HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade haproxy | Apr 25, 2025 | Apr 9, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade haproxy | Aug 13, 2025 | Jul 18, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade haproxy | Jul 21, 2025 | Apr 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade haproxy | Aug 13, 2025 | Jul 18, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 9, 2025 |
| Suse | — | Upgrade haproxy | Dec 5, 2025 | Apr 15, 2025 |
| Ubuntu | — | Upgrade haproxy | Apr 14, 2025 | Apr 9, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Apr 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub