HAProxy's vulnerability footprint, despite a narrow product portfolio, spans a prominent set of load-balancing and reverse-proxy appliances and controllers that sit in the request path of critical infrastructure and cloud deployments, making the vendor's disclosures material to a broad operational constituency. The vendor's vulnerabilities display a moderate tendency toward critical severity and cluster around parser-oriented and memory-safety weakness classes, including buffer-boundary violations, HTTP request smuggling, infinite-loop conditions, and out-of-bounds reads that are characteristic of protocol-handling and proxy logic. The recurring products—HAProxy itself, Aloha appliances, HAProxy Enterprise, and Kubernetes ingress controllers—reflect the vendor's role across both standalone and orchestrated environments, where a single flaw in request parsing or routing can affect downstream services across an infrastructure. Defenders should prioritize tracking this vendor's advisories and treat exposed proxy instances as high-patching-priority assets; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haproxy over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14241HIGH HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c. | Jul 23, 2019 | 7.5 | 63 | NO | NO |
CVE-2021-40346HIGH An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all config | Sep 8, 2021 | 7.5 | 54 | NO | NO |
CVE-2020-11100HIGH In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap v | Apr 2, 2020 | 8.8 | 54 | NO | NO |
CVE-2016-5360HIGH HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have uns | Jun 30, 2016 | 7.5 | 46 | NO | NO |
CVE-2026-55203CRITICAL HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record hea | Jun 18, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-55204HIGH HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return va | Jun 18, 2026 | 7.5 | 34 | NO | NO |
CVE-2019-19330CRITICAL The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, A | Nov 27, 2019 | 9.8 | 31 | NO | NO |
CVE-2023-25725CRITICAL HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAPr | Feb 14, 2023 | 9.1 | 30 | NO | NO |
CVE-2026-33555MEDIUM An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is clo | Apr 13, 2026 | 5.8 | 28 | NO | NO |
CVE-2019-18277HIGH A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact wa | Oct 23, 2019 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haproxy.
Media articles that mention a CVE ID that affects a product developed by Haproxy — matched by CVE ID, not by vendor name.