Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11230

Опубликовано: 03 окт. 2025
Источник: redhat
CVSS3: 7.5

Описание

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

A flaw was found in haproxy. A stemming from an inefficient algorithmic complexity issue within its bundled mjson parsing library. This vulnerability is triggered when haproxy is configured to analyze JSON content, such as with the json_query or jwt_payload_query function

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5haproxyAffected
Red Hat Enterprise Linux 7haproxyAffected
Red Hat Enterprise Linux 8haproxyNot affected
Red Hat OpenShift Container Platform 4haproxyNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-haproxy-routerAffected
Red Hat OpenShift Container Platform 4openshift4/ose-haproxy-router-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel8Affected
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Affected
Red Hat OpenShift Container Platform 4openshift4/ose-testsAffected
Red Hat OpenShift Container Platform 4openshift4/ose-tests-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=2413003haproxy: denial of service vulnerability in HAProxy mjson library

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

CVSS3: 7.5
nvd
5 месяцев назад

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

CVSS3: 7.5
msrc
5 месяцев назад

Denial of service vulnerability in HAProxy mjson library

CVSS3: 7.5
debian
5 месяцев назад

Inefficient algorithm complexity in mjson in HAProxy allows remote att ...

suse-cvrf
3 месяца назад

Security update for haproxy

7.5 High

CVSS3