<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:14:03 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:1696 — Moderate: haproxy security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:1696</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: haproxy&lt;/p&gt;
&lt;p&gt;The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* haproxy: segfault DoS (CVE-2023-0056)
* haproxy: request smuggling attack in HTTP/1 header parsing (CVE-2023-25725)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: haproxy&lt;/p&gt;
&lt;p&gt;The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* haproxy: segfault DoS (CVE-2023-0056)
* haproxy: request smuggling attack in HTTP/1 header parsing (CVE-2023-25725)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:1696</guid>
    </item>
    <item>
      <title>bdu:2023-04835</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04835</link>
      <description>bdu:2023-04835</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04835</guid>
    </item>
    <item>
      <title>EUVD-2026-219025</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-219025</link>
      <description>EUVD-2026-219025</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-219025</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0056</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0056</link>
      <description>&lt;p&gt;An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0056</guid>
    </item>
    <item>
      <title>GHSA-43q4-pf55-3xhc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43q4-pf55-3xhc</link>
      <description>&lt;p&gt;An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43q4-pf55-3xhc</guid>
    </item>
    <item>
      <title>gsd-2023-0056</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0056</link>
      <description>gsd-2023-0056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0056</guid>
    </item>
    <item>
      <title>OESA-2023-1141 — haproxy security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1141</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: haproxy, openEuler:20.03-LTS-SP3: haproxy, openEuler:22.03-LTS: haproxy, openEuler:22.03-LTS-SP1: haproxy&lt;/p&gt;
&lt;p&gt;HAProxy is a free, very fast and reliable solution offering high availability, load balancing, and proxying for TCP and HTTP-based applications. It is particularly suited for very high traffic web sites and powers quite a number of the world&amp;#39;s most visited ones. &#13;
&#13;
Security Fix(es):&#13;
&#13;
Initial description: Router PODs frequently getting restarted and haproxy process is receiving the segfault but it is not generating coredump even though the core file size is unlimited.&#13;
&#13;
Upstream bug: https://github.com/haproxy/haproxy/issues/1972(CVE-2023-0056)&#13;
&#13;
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka &amp;amp;quot;request smuggling.&amp;amp;quot; The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.(CVE-2023-25725)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: haproxy, openEuler:20.03-LTS-SP3: haproxy, openEuler:22.03-LTS: haproxy, openEuler:22.03-LTS-SP1: haproxy&lt;/p&gt;
&lt;p&gt;HAProxy is a free, very fast and reliable solution offering high availability, load balancing, and proxying for TCP and HTTP-based applications. It is particularly suited for very high traffic web sites and powers quite a number of the world&amp;#39;s most visited ones. &#13;
&#13;
Security Fix(es):&#13;
&#13;
Initial description: Router PODs frequently getting restarted and haproxy process is receiving the segfault but it is not generating coredump even though the core file size is unlimited.&#13;
&#13;
Upstream bug: https://github.com/haproxy/haproxy/issues/1972(CVE-2023-0056)&#13;
&#13;
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka &amp;amp;quot;request smuggling.&amp;amp;quot; The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.(CVE-2023-25725)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1141</guid>
    </item>
    <item>
      <title>RHBA-2023:0773 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.11.28 packages update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:0773</link>
      <description>&lt;p&gt;haproxy: segfault DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;haproxy: segfault DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:0773</guid>
    </item>
    <item>
      <title>RHSA-2023:1696 — Red Hat Security Advisory: haproxy security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1696</link>
      <description>&lt;p&gt;haproxy: segfault DoS haproxy: request smuggling attack in HTTP/1 header parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;haproxy: segfault DoS haproxy: request smuggling attack in HTTP/1 header parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1696</guid>
    </item>
    <item>
      <title>SUSE-FU-2023:2117-1 — Feature update for haproxy</title>
      <link>https://cve.radiocsirt.org/vuln/suse-fu-2023:2117-1</link>
      <description>&lt;p&gt;Feature update for haproxy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Feature update for haproxy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-fu-2023:2117-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-0056</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0056</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: haproxy, Ubuntu:22.04:LTS: haproxy&lt;/p&gt;
&lt;p&gt;An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: haproxy, Ubuntu:22.04:LTS: haproxy&lt;/p&gt;
&lt;p&gt;An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0056</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0097 — HAProxy: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0097</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in HAProxy ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in HAProxy ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0097</guid>
    </item>
  </channel>
</rss>
