VYPR
Critical severity9.8NVD Advisory· Published Nov 27, 2019· Updated Jun 17, 2026

CVE-2019-19330

CVE-2019-19330

Description

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Haproxy/Haproxy2 versions
    cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*range: <2.0.10
    • (no CPE)range: <2.0.10
  • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • HAProxy/HAProxydescription

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.