Vulnerability Database

313,825

Total vulnerabilities in the database

CVE-2025-11230

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

  • Published: Nov 19, 2025
  • Updated: Nov 20, 2025
  • CVE: CVE-2025-11230
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CWEs:

Software From Fixed in
haproxy / aloha_appliance 14.5.0 14.5.33
haproxy / aloha_appliance 15.5.0 15.5.28
haproxy / aloha_appliance 16.5.0 16.5.19
haproxy / aloha_appliance 17.0.0 17.0.7
haproxy / haproxy 2.4.0 2.4.30
haproxy / haproxy 2.6.0 2.6.23
haproxy / haproxy 2.8.0 2.8.16
haproxy / haproxy 3.0.0 3.0.12
haproxy / haproxy 3.1.0 3.1.9
haproxy / haproxy 3.2.0 3.2.6
haproxy / haproxy_enterprise 2.4r1-1.0.0-253.271 2.4r1-1.0.0-253.271.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-254.271 2.4r1-1.0.0-254.271.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-259.342 2.4r1-1.0.0-259.342.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-263.343 2.4r1-1.0.0-263.343.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-264.356 2.4r1-1.0.0-264.356.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.356 2.4r1-1.0.0-268.356.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.373 2.4r1-1.0.0-268.373.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.459 2.4r1-1.0.0-268.459.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.464 2.4r1-1.0.0-268.464.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.477 2.4r1-1.0.0-268.477.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.499 2.4r1-1.0.0-268.499.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.553 2.4r1-1.0.0-268.553.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.560 2.4r1-1.0.0-268.560.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.564 2.4r1-1.0.0-268.564.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-268.596 2.4r1-1.0.0-268.596.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-269.596 2.4r1-1.0.0-269.596.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-269.599 2.4r1-1.0.0-269.599.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-270.616 2.4r1-1.0.0-270.616.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-271.673 2.4r1-1.0.0-271.673.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-271.677 2.4r1-1.0.0-271.677.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-272.683 2.4r1-1.0.0-272.683.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-272.686 2.4r1-1.0.0-272.686.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-272.728 2.4r1-1.0.0-272.728.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-274.752 2.4r1-1.0.0-274.752.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-276.752 2.4r1-1.0.0-276.752.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-277.814 2.4r1-1.0.0-277.814.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-277.831 2.4r1-1.0.0-277.831.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-278.838 2.4r1-1.0.0-278.838.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.852 2.4r1-1.0.0-279.852.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.859 2.4r1-1.0.0-279.859.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.877 2.4r1-1.0.0-279.877.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.911 2.4r1-1.0.0-279.911.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.940 2.4r1-1.0.0-279.940.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.952 2.4r1-1.0.0-279.952.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.953 2.4r1-1.0.0-279.953.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-279.956 2.4r1-1.0.0-279.956.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-280.956 2.4r1-1.0.0-280.956.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-282.998 2.4r1-1.0.0-282.998.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-282.999 2.4r1-1.0.0-282.999.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-284.999 2.4r1-1.0.0-284.999.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-285.1010 2.4r1-1.0.0-285.1010.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-286.1064 2.4r1-1.0.0-286.1064.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-286.1068 2.4r1-1.0.0-286.1068.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-286.1089 2.4r1-1.0.0-286.1089.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-286.1094 2.4r1-1.0.0-286.1094.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-288.1094 2.4r1-1.0.0-288.1094.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-288.1158 2.4r1-1.0.0-288.1158.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-288.1167 2.4r1-1.0.0-288.1167.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-288.1189 2.4r1-1.0.0-288.1189.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-289.1189 2.4r1-1.0.0-289.1189.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-290.1239 2.4r1-1.0.0-290.1239.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-291.1246 2.4r1-1.0.0-291.1246.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-292.1293 2.4r1-1.0.0-292.1293.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-294.1346 2.4r1-1.0.0-294.1346.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-294.1364 2.4r1-1.0.0-294.1364.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-294.1376 2.4r1-1.0.0-294.1376.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-294.1377 2.4r1-1.0.0-294.1377.x
haproxy / haproxy_enterprise 2.4r1-1.0.0-294.1442 2.4r1-1.0.0-294.1442.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-281.466 2.6r1-1.0.0-281.466.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-282.561 2.6r1-1.0.0-282.561.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-283.562 2.6r1-1.0.0-283.562.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-283.565 2.6r1-1.0.0-283.565.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-283.616 2.6r1-1.0.0-283.616.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-283.632 2.6r1-1.0.0-283.632.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-283.633 2.6r1-1.0.0-283.633.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-283.636 2.6r1-1.0.0-283.636.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-284.636 2.6r1-1.0.0-284.636.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-285.726 2.6r1-1.0.0-285.726.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-285.727 2.6r1-1.0.0-285.727.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-287.727 2.6r1-1.0.0-287.727.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-288.770 2.6r1-1.0.0-288.770.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-288.773 2.6r1-1.0.0-288.773.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-288.848 2.6r1-1.0.0-288.848.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-288.849 2.6r1-1.0.0-288.849.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-289.1020 2.6r1-1.0.0-289.1020.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-289.1028 2.6r1-1.0.0-289.1028.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-289.1041 2.6r1-1.0.0-289.1041.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-289.873 2.6r1-1.0.0-289.873.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-289.975 2.6r1-1.0.0-289.975.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-289.976 2.6r1-1.0.0-289.976.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-291.1046 2.6r1-1.0.0-291.1046.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1046 2.6r1-1.0.0-292.1046.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1055 2.6r1-1.0.0-292.1055.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1120 2.6r1-1.0.0-292.1120.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1147 2.6r1-1.0.0-292.1147.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1148 2.6r1-1.0.0-292.1148.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1156 2.6r1-1.0.0-292.1156.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1181 2.6r1-1.0.0-292.1181.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-292.1187 2.6r1-1.0.0-292.1187.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-293.1189 2.6r1-1.0.0-293.1189.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-293.1190 2.6r1-1.0.0-293.1190.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-294.1212 2.6r1-1.0.0-294.1212.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-294.1285 2.6r1-1.0.0-294.1285.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-295.1303 2.6r1-1.0.0-295.1303.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-296.1392 2.6r1-1.0.0-296.1392.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-296.1416 2.6r1-1.0.0-296.1416.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1416 2.6r1-1.0.0-299.1416.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1474 2.6r1-1.0.0-299.1474.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1487 2.6r1-1.0.0-299.1487.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1511 2.6r1-1.0.0-299.1511.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1542 2.6r1-1.0.0-299.1542.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1557 2.6r1-1.0.0-299.1557.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1596 2.6r1-1.0.0-299.1596.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1603 2.6r1-1.0.0-299.1603.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1606 2.6r1-1.0.0-299.1606.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-299.1618 2.6r1-1.0.0-299.1618.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-300.1666 2.6r1-1.0.0-300.1666.x
haproxy / haproxy_enterprise 2.6r1-1.0.0-301.1666 2.6r1-1.0.0-301.1666.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-302.234 2.8r1-1.0.0-302.234.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-304.266 2.8r1-1.0.0-304.266.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-305.279 2.8r1-1.0.0-305.279.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-305.285 2.8r1-1.0.0-305.285.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-306.288 2.8r1-1.0.0-306.288.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-306.289 2.8r1-1.0.0-306.289.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-307.317 2.8r1-1.0.0-307.317.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-310.350 2.8r1-1.0.0-310.350.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-310.364 2.8r1-1.0.0-310.364.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-310.373 2.8r1-1.0.0-310.373.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-310.374 2.8r1-1.0.0-310.374.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-310.418 2.8r1-1.0.0-310.418.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-310.422 2.8r1-1.0.0-310.422.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-310.424 2.8r1-1.0.0-310.424.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-311.449 2.8r1-1.0.0-311.449.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-311.452 2.8r1-1.0.0-311.452.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-311.453 2.8r1-1.0.0-311.453.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-312.592 2.8r1-1.0.0-312.592.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-312.613 2.8r1-1.0.0-312.613.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-317.613 2.8r1-1.0.0-317.613.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-318.674 2.8r1-1.0.0-318.674.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-319.699 2.8r1-1.0.0-319.699.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-319.723 2.8r1-1.0.0-319.723.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.750 2.8r1-1.0.0-320.750.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.761 2.8r1-1.0.0-320.761.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.770 2.8r1-1.0.0-320.770.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.780 2.8r1-1.0.0-320.780.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.781 2.8r1-1.0.0-320.781.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.783 2.8r1-1.0.0-320.783.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.831 2.8r1-1.0.0-320.831.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.851 2.8r1-1.0.0-320.851.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.853 2.8r1-1.0.0-320.853.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-320.895 2.8r1-1.0.0-320.895.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-321.895 2.8r1-1.0.0-321.895.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-321.901 2.8r1-1.0.0-321.901.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-321.919 2.8r1-1.0.0-321.919.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-321.931 2.8r1-1.0.0-321.931.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-321.934 2.8r1-1.0.0-321.934.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-321.937 2.8r1-1.0.0-321.937.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-322.942 2.8r1-1.0.0-322.942.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-324.1030 2.8r1-1.0.0-324.1030.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-324.1071 2.8r1-1.0.0-324.1071.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-324.1072 2.8r1-1.0.0-324.1072.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-324.947 2.8r1-1.0.0-324.947.x
haproxy / haproxy_enterprise 2.8r1-1.0.0-326.1073 2.8r1-1.0.0-326.1073.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-337.363 3.0r1-1.0.0-337.363.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-337.390 3.0r1-1.0.0-337.390.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-337.394 3.0r1-1.0.0-337.394.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-339.395 3.0r1-1.0.0-339.395.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-339.405 3.0r1-1.0.0-339.405.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-339.415 3.0r1-1.0.0-339.415.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-339.455 3.0r1-1.0.0-339.455.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-339.466 3.0r1-1.0.0-339.466.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-339.471 3.0r1-1.0.0-339.471.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-341.475 3.0r1-1.0.0-341.475.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-342.482 3.0r1-1.0.0-342.482.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.495 3.0r1-1.0.0-344.495.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.503 3.0r1-1.0.0-344.503.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.561 3.0r1-1.0.0-344.561.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.564 3.0r1-1.0.0-344.564.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.591 3.0r1-1.0.0-344.591.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.608 3.0r1-1.0.0-344.608.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.641 3.0r1-1.0.0-344.641.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.655 3.0r1-1.0.0-344.655.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-344.672 3.0r1-1.0.0-344.672.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-345.673 3.0r1-1.0.0-345.673.x
haproxy / haproxy_enterprise 3.0r1-1.0.0-346.792 3.0r1-1.0.0-346.792.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-345.233 3.1r1-1.0.0-345.233.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-346.274 3.1r1-1.0.0-346.274.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-346.287 3.1r1-1.0.0-346.287.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-347.299 3.1r1-1.0.0-347.299.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-347.338 3.1r1-1.0.0-347.338.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-347.362 3.1r1-1.0.0-347.362.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-347.405 3.1r1-1.0.0-347.405.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-347.419 3.1r1-1.0.0-347.419.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-347.431 3.1r1-1.0.0-347.431.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-347.449 3.1r1-1.0.0-347.449.x
haproxy / haproxy_enterprise 3.1r1-1.0.0-348.519 3.1r1-1.0.0-348.519.x
haproxy / kubernetes_ingress_controller - 1.9.14-ee7
haproxy / kubernetes_ingress_controller - 3.1.12
haproxy / kubernetes_ingress_controller 1.10.10-ee1 1.11.12-ee10
haproxy / kubernetes_ingress_controller 3.0.0-ee1 3.0.15-ee4