HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 14 Oct 2024 03:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service. | HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024. | 
Fri, 06 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Fri, 06 Sep 2024 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Thu, 05 Sep 2024 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:haproxy:haproxy:3.1:dev0:*:*:*:*:*:* cpe:2.3:a:haproxy:haproxy:3.1:dev1:*:*:*:*:*:* cpe:2.3:a:haproxy:haproxy:3.1:dev2:*:*:*:*:*:* cpe:2.3:a:haproxy:haproxy:3.1:dev3:*:*:*:*:*:* cpe:2.3:a:haproxy:haproxy:3.1:dev4:*:*:*:*:*:* cpe:2.3:a:haproxy:haproxy:3.1:dev5:*:*:*:*:*:* | 
Wed, 04 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | haproxy: potential infinite loop condition in the h2_send() may trigger a DoS | |
| Weaknesses | CWE-835 | |
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Wed, 04 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Haproxy Haproxy haproxy | |
| CPEs | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* | |
| Vendors & Products | Haproxy Haproxy haproxy | |
| Metrics | cvssV3_1 
 
 | 
Wed, 04 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service. | |
| References |  | 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2024-09-04T00:00:00.000Z
Updated: 2025-03-14T19:16:38.990Z
Reserved: 2024-09-01T00:00:00.000Z
Link: CVE-2024-45506
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-09-04T16:10:30.999Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-09-04T15:15:14.080
Modified: 2025-03-14T20:15:13.870
Link: CVE-2024-45506
 Redhat
                        Redhat