HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
{
"versions": [
{
"introduced": "2.9.0"
},
{
"fixed": "2.9.10"
},
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.1-dev0"
},
{
"introduced": "0"
},
{
"last_affected": "3.1-dev1"
},
{
"introduced": "0"
},
{
"last_affected": "3.1-dev2"
},
{
"introduced": "0"
},
{
"last_affected": "3.1-dev3"
},
{
"introduced": "0"
},
{
"last_affected": "3.1-dev4"
},
{
"introduced": "0"
},
{
"last_affected": "3.1-dev5"
}
]
}