CVE-2025-11230

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
canonicalCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
haproxyaloha_appliance
14.5.0 ≤
𝑥
< 14.5.33
haproxyaloha_appliance
15.5.0 ≤
𝑥
< 15.5.28
haproxyaloha_appliance
16.5.0 ≤
𝑥
< 16.5.19
haproxyaloha_appliance
17.0.0 ≤
𝑥
< 17.0.7
haproxyhaproxy
2.4.0 ≤
𝑥
< 2.4.30
haproxyhaproxy
2.6.0 ≤
𝑥
< 2.6.23
haproxyhaproxy
2.8.0 ≤
𝑥
< 2.8.16
haproxyhaproxy
3.0.0 ≤
𝑥
< 3.0.12
haproxyhaproxy
3.1.0 ≤
𝑥
< 3.1.9
haproxyhaproxy
3.2.0 ≤
𝑥
< 3.2.6
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.4r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.6r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
2.8r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.0r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxyhaproxy_enterprise
3.1r1:r1
haproxykubernetes_ingress_controller
𝑥
< 1.9.14-ee7
haproxykubernetes_ingress_controller
𝑥
< 3.1.12
haproxykubernetes_ingress_controller
1.10.10-ee1 ≤
𝑥
< 1.11.12-ee10
haproxykubernetes_ingress_controller
3.0.0-ee1 ≤
𝑥
< 3.0.15-ee4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
haproxy
bullseye
2.2.9-2+deb11u6
not-affected
bullseye (security)
2.2.9-2+deb11u7
fixed
bookworm
vulnerable
bookworm (security)
2.6.12-1+deb12u3
fixed
trixie (security)
3.0.11-1+deb13u1
fixed
trixie
3.0.11-1+deb13u1
fixed
forky
3.2.10-1
fixed
sid
3.2.10-1
fixed