Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Haproxy

First CVE: May 27, 2012Active for: 14 yearsTotal CVEs: 38
46.4
VTI Score
High

HAProxy's vulnerability footprint, despite a narrow product portfolio, spans a prominent set of load-balancing and reverse-proxy appliances and controllers that sit in the request path of critical infrastructure and cloud deployments, making the vendor's disclosures material to a broad operational constituency. The vendor's vulnerabilities display a moderate tendency toward critical severity and cluster around parser-oriented and memory-safety weakness classes, including buffer-boundary violations, HTTP request smuggling, infinite-loop conditions, and out-of-bounds reads that are characteristic of protocol-handling and proxy logic. The recurring products—HAProxy itself, Aloha appliances, HAProxy Enterprise, and Kubernetes ingress controllers—reflect the vendor's role across both standalone and orchestrated environments, where a single flaw in request parsing or routing can affect downstream services across an infrastructure. Defenders should prioritize tracking this vendor's advisories and treat exposed proxy instances as high-patching-priority assets; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Haproxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 27, 2012
14 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-14241HIGH
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.
Jul 23, 20197.563NONO
CVE-2021-40346HIGH
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all config
Sep 8, 20217.554NONO
CVE-2020-11100HIGH
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap v
Apr 2, 20208.854NONO
CVE-2016-5360HIGH
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have uns
Jun 30, 20167.546NONO
CVE-2026-55203CRITICAL
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record hea
Jun 18, 20269.138NONO
CVE-2026-55204HIGH
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return va
Jun 18, 20267.534NONO
CVE-2019-19330CRITICAL
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, A
Nov 27, 20199.831NONO
CVE-2023-25725CRITICAL
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAPr
Feb 14, 20239.130NONO
CVE-2026-33555MEDIUM
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is clo
Apr 13, 20265.828NONO
CVE-2019-18277HIGH
A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact wa
Oct 23, 20197.528NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
34%
55%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (86.8%)
Unknown5 (13.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (73.7%)
High5 (13.2%)
Unknown5 (13.2%)
User Interaction
None33 (86.8%)
Unknown5 (13.2%)
Required0 (0.0%)
Privileges Required
Low2 (5.3%)
High0 (0.0%)
None31 (81.6%)
Unknown5 (13.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Haproxy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Haproxy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Haproxy's Products

View all 6 CNAs →

Top CWEs