VYPR

apk package

chainguard/haproxy-2.8-oci-entrypoint

pkg:apk/chainguard/haproxy-2.8-oci-entrypoint

Vulnerabilities (5)

  • CVE-2025-11230Nov 19, 2025
    affected < 2.8.18-r0fixed 2.8.18-r0

    Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

  • CVE-2025-32464MedApr 9, 2025
    affected < 2.8.13-r45fixed 2.8.13-r45

    HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

  • CVE-2024-53008MedNov 28, 2024
    affected < 2.8.13-r0fixed 2.8.13-r0

    Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obt

  • CVE-2023-0056Mar 23, 2023
    affected < 0fixed 0

    An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

  • CVE-2016-2102MedAug 22, 2017
    affected < 0fixed 0

    HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.