Critical severity9.8NVD Advisory· Published Nov 27, 2019· Updated Jun 17, 2026
CVE-2019-19330
CVE-2019-19330
Description
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- HAProxy/HAProxydescription
Patches
Vulnerability mechanics
References
8- seclists.org/bugtraq/2019/Nov/45nvdMailing ListThird Party Advisory
- tools.ietf.org/html/rfc7540nvdThird Party Advisory
- usn.ubuntu.com/4212-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4577nvdThird Party Advisory
- git.haproxy.orgnvd
- git.haproxy.orgnvd
- git.haproxy.orgnvd
- security.gentoo.org/glsa/202004-01nvd
News mentions
0No linked articles in our index yet.