Количество 12
Количество 12
GHSA-5mp8-rq5m-pj7m
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser doe ...
openSUSE-SU-2026:20618-1
Security update for haproxy
SUSE-SU-2026:1568-1
Security update for haproxy
ROS-20260922-80-0164
Уязвимость haproxy2
ROS-20260922-80-0163
Уязвимость haproxy
ROS-20260922-73-0130
Уязвимость haproxy
ROS-20260922-73-0129
Уязвимость haproxy2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-5mp8-rq5m-pj7m An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser doe ... | CVSS3: 4 | 0% Низкий | 5 месяцев назад | |
openSUSE-SU-2026:20618-1 Security update for haproxy | 0% Низкий | 5 месяцев назад | ||
SUSE-SU-2026:1568-1 Security update for haproxy | 0% Низкий | 5 месяцев назад | ||
ROS-20260922-80-0164 Уязвимость haproxy2 | CVSS3: 5.8 | 0% Низкий | 3 дня назад | |
ROS-20260922-80-0163 Уязвимость haproxy | CVSS3: 5.8 | 0% Низкий | 3 дня назад | |
ROS-20260922-73-0130 Уязвимость haproxy | CVSS3: 5.8 | 0% Низкий | 3 дня назад | |
ROS-20260922-73-0129 Уязвимость haproxy2 | CVSS3: 5.8 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу