High severity8.8NVD Advisory· Published Apr 2, 2020· Updated Jun 17, 2026
CVE-2020-11100
CVE-2020-11100
Description
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- HAProxy/HAProxydescription
- osv-coords5 versionspkg:bitnami/haproxypkg:rpm/opensuse/haproxy&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/haproxy&distro=openSUSE%20Tumbleweedpkg:rpm/suse/haproxy&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/haproxy&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1
>= 1.8.0, < 2.1.4+ 4 more
- (no CPE)range: >= 1.8.0, < 2.1.4
- (no CPE)range: < 2.0.10+git0.ac198b92-lp151.2.9.1
- (no CPE)range: < 2.4.4+git0.acb1d0bea-1.2
- (no CPE)range: < 2.0.10+git0.ac198b92-3.19.1
- (no CPE)range: < 2.0.10+git0.ac198b92-8.12.1
Patches
Vulnerability mechanics
References
14- lists.opensuse.org/opensuse-security-announce/2020-04/msg00002.htmlnvdMailing ListThird Party Advisory
- packetstormsecurity.com/files/157323/haproxy-hpack-tbl.c-Out-Of-Bounds-Write.htmlnvdThird Party AdvisoryVDB Entry
- www.haproxy.orgnvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-security-announce/2020/msg00052.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202012-22nvdThird Party Advisory
- usn.ubuntu.com/4321-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4649nvdThird Party Advisory
- www.haproxy.org/download/2.1/src/CHANGELOGnvdRelease NotesVendor Advisory
- git.haproxy.orgnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/264C7UL3X7L7QE74ZJ557IOUFS3J4QQC/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNW5RZLIX7LOXRLV7WMHX22CI43XSXKW/nvd
- www.mail-archive.com/haproxy%40formilux.org/msg36876.htmlnvd
News mentions
0No linked articles in our index yet.