CVE-2024-45506
04.09.2024, 15:15
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
Vendor | Product | Version |
---|---|---|
haproxy | haproxy | 2.9.0 ≤ 𝑥 < 2.9.10 |
haproxy | haproxy | 3.0.0 ≤ 𝑥 < 3.0.4 |
haproxy | haproxy | 3.1:dev0 |
haproxy | haproxy | 3.1:dev1 |
haproxy | haproxy | 3.1:dev2 |
haproxy | haproxy | 3.1:dev3 |
haproxy | haproxy | 3.1:dev4 |
haproxy | haproxy | 3.1:dev5 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References