Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-70538.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-70538
Upstream
Published
2025-11-19T10:15:45Z
Modified
2026-04-21T04:36:25.416120Z
Summary
CVE-2025-11230 affecting package haproxy for versions less than 2.4.24-2
Details

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

References

Affected packages

Azure Linux:2 / haproxy

Package

Name
haproxy
Purl
pkg:rpm/azure-linux/haproxy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.24-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-70538.json"