[WID-SEC-2026-3323] HAProxy: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 13.09.2026 Stand 14.09.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung HAProxy ist ein weit verbreiteter Open Source Software Load Balancer und Application Delivery Controller. Produkte 13.09.2026 HAProxy HAProxy <=3.4.4 HAProxy HAProxy <3.5-dev6 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in HAProxy ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren und einen Denial-of-Service-Zustand auszulösen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A remote, anonymous attacker can exploit a vulnerability in HAProxy to bypass security controls, manipulate data, and cause a denial-of-service condition. The vulnerability has a high CVSS base score of 7.5 and affects HAProxy versions up to and including 3.4.4, as well as development versions prior to 3.5-dev6. A mitigation is available, though the article does not specify a fixed version or detailed workaround.