Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-48668.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-48668
Upstream
Published
2024-09-04T15:15:14Z
Modified
2026-04-01T05:17:14.216682Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
CVE-2024-45506 affecting package haproxy for versions less than 2.9.11-1
Details

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

References

Affected packages

Azure Linux:3 / haproxy

Package

Name
haproxy
Purl
pkg:rpm/azure-linux/haproxy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.11-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-48668.json"