CVE-2024-45506

HIGH EXPLOITED IN THE WILD

HAProxy <2.9.10, <3.0.4, <=3.1-dev6 - DoS

Title source: llm
STIX 2.1

Description

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

Scores

CVSS v3 7.5
EPSS 0.0149
EPSS Percentile 81.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2024-09-03
InTheWild.io 2024-10-14
CWE
CWE-835
Status published
Products (2)
haproxy/haproxy 3.1 dev0 (6 CPE variants)
haproxy/haproxy 2.9.0 - 2.9.10
Published Sep 04, 2024
Tracked Since Feb 18, 2026