Vulnerability Database

387,360

Total vulnerabilities in the database

CVE-2025-11230 — haproxy / aloha_appliance

Inefficient Algorithmic Complexity

Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

  • Published: Nov 19, 2025
  • Updated: Sep 18, 2026
  • CVE: CVE-2025-11230
  • Severity: High
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CWEs:

Software Affected versions
haproxy / aloha_appliance >= 14.5.0, < 14.5.33
haproxy / aloha_appliance >= 15.5.0, < 15.5.28
haproxy / aloha_appliance >= 16.5.0, < 16.5.19
haproxy / aloha_appliance >= 17.0.0, < 17.0.7
haproxy / haproxy >= 2.4.0, < 2.4.30
haproxy / haproxy >= 2.6.0, < 2.6.23
haproxy / haproxy >= 2.8.0, < 2.8.16
haproxy / haproxy >= 3.0.0, < 3.0.12
haproxy / haproxy >= 3.1.0, < 3.1.9
haproxy / haproxy >= 3.2.0, < 3.2.6
haproxy / kubernetes_ingress_controller < 1.9.14-ee7
haproxy / kubernetes_ingress_controller < 3.1.12
haproxy / kubernetes_ingress_controller >= 1.10.10-ee1, < 1.11.12-ee10
haproxy / kubernetes_ingress_controller >= 3.0.0-ee1, < 3.0.15-ee4
haproxy / haproxy_enterprise = 2.4r1-1.0.0-253.271
haproxy / haproxy_enterprise = 2.4r1-1.0.0-254.271
haproxy / haproxy_enterprise = 2.4r1-1.0.0-259.342
haproxy / haproxy_enterprise = 2.4r1-1.0.0-263.343
haproxy / haproxy_enterprise = 2.4r1-1.0.0-264.356
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.356
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.373
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.459
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.464
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.477
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.499
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.553
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.560
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.564
haproxy / haproxy_enterprise = 2.4r1-1.0.0-268.596
haproxy / haproxy_enterprise = 2.4r1-1.0.0-269.596
haproxy / haproxy_enterprise = 2.4r1-1.0.0-269.599
haproxy / haproxy_enterprise = 2.4r1-1.0.0-270.616
haproxy / haproxy_enterprise = 2.4r1-1.0.0-271.673
haproxy / haproxy_enterprise = 2.4r1-1.0.0-271.677
haproxy / haproxy_enterprise = 2.4r1-1.0.0-272.683
haproxy / haproxy_enterprise = 2.4r1-1.0.0-272.686
haproxy / haproxy_enterprise = 2.4r1-1.0.0-272.728
haproxy / haproxy_enterprise = 2.4r1-1.0.0-274.752
haproxy / haproxy_enterprise = 2.4r1-1.0.0-276.752
haproxy / haproxy_enterprise = 2.4r1-1.0.0-277.814
haproxy / haproxy_enterprise = 2.4r1-1.0.0-277.831
haproxy / haproxy_enterprise = 2.4r1-1.0.0-278.838
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.852
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.859
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.877
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.911
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.940
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.952
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.953
haproxy / haproxy_enterprise = 2.4r1-1.0.0-279.956
haproxy / haproxy_enterprise = 2.4r1-1.0.0-280.956
haproxy / haproxy_enterprise = 2.4r1-1.0.0-282.998
haproxy / haproxy_enterprise = 2.4r1-1.0.0-282.999
haproxy / haproxy_enterprise = 2.4r1-1.0.0-284.999
haproxy / haproxy_enterprise = 2.4r1-1.0.0-285.1010
haproxy / haproxy_enterprise = 2.4r1-1.0.0-286.1064
haproxy / haproxy_enterprise = 2.4r1-1.0.0-286.1068
haproxy / haproxy_enterprise = 2.4r1-1.0.0-286.1089
haproxy / haproxy_enterprise = 2.4r1-1.0.0-286.1094
haproxy / haproxy_enterprise = 2.4r1-1.0.0-288.1094
haproxy / haproxy_enterprise = 2.4r1-1.0.0-288.1158
haproxy / haproxy_enterprise = 2.4r1-1.0.0-288.1167
haproxy / haproxy_enterprise = 2.4r1-1.0.0-288.1189
haproxy / haproxy_enterprise = 2.4r1-1.0.0-289.1189
haproxy / haproxy_enterprise = 2.4r1-1.0.0-290.1239
haproxy / haproxy_enterprise = 2.4r1-1.0.0-291.1246
haproxy / haproxy_enterprise = 2.4r1-1.0.0-292.1293
haproxy / haproxy_enterprise = 2.4r1-1.0.0-294.1346
haproxy / haproxy_enterprise = 2.4r1-1.0.0-294.1364
haproxy / haproxy_enterprise = 2.4r1-1.0.0-294.1376
haproxy / haproxy_enterprise = 2.4r1-1.0.0-294.1377
haproxy / haproxy_enterprise = 2.4r1-1.0.0-294.1442
haproxy / haproxy_enterprise = 2.6r1-1.0.0-281.466
haproxy / haproxy_enterprise = 2.6r1-1.0.0-282.561
haproxy / haproxy_enterprise = 2.6r1-1.0.0-283.562
haproxy / haproxy_enterprise = 2.6r1-1.0.0-283.565
haproxy / haproxy_enterprise = 2.6r1-1.0.0-283.616
haproxy / haproxy_enterprise = 2.6r1-1.0.0-283.632
haproxy / haproxy_enterprise = 2.6r1-1.0.0-283.633
haproxy / haproxy_enterprise = 2.6r1-1.0.0-283.636
haproxy / haproxy_enterprise = 2.6r1-1.0.0-284.636
haproxy / haproxy_enterprise = 2.6r1-1.0.0-285.726
haproxy / haproxy_enterprise = 2.6r1-1.0.0-285.727
haproxy / haproxy_enterprise = 2.6r1-1.0.0-287.727
haproxy / haproxy_enterprise = 2.6r1-1.0.0-288.770
haproxy / haproxy_enterprise = 2.6r1-1.0.0-288.773
haproxy / haproxy_enterprise = 2.6r1-1.0.0-288.848
haproxy / haproxy_enterprise = 2.6r1-1.0.0-288.849
haproxy / haproxy_enterprise = 2.6r1-1.0.0-289.1020
haproxy / haproxy_enterprise = 2.6r1-1.0.0-289.1028
haproxy / haproxy_enterprise = 2.6r1-1.0.0-289.1041
haproxy / haproxy_enterprise = 2.6r1-1.0.0-289.873
haproxy / haproxy_enterprise = 2.6r1-1.0.0-289.975
haproxy / haproxy_enterprise = 2.6r1-1.0.0-289.976
haproxy / haproxy_enterprise = 2.6r1-1.0.0-291.1046
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1046
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1055
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1120
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1147
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1148
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1156
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1181
haproxy / haproxy_enterprise = 2.6r1-1.0.0-292.1187
haproxy / haproxy_enterprise = 2.6r1-1.0.0-293.1189
haproxy / haproxy_enterprise = 2.6r1-1.0.0-293.1190
haproxy / haproxy_enterprise = 2.6r1-1.0.0-294.1212
haproxy / haproxy_enterprise = 2.6r1-1.0.0-294.1285
haproxy / haproxy_enterprise = 2.6r1-1.0.0-295.1303
haproxy / haproxy_enterprise = 2.6r1-1.0.0-296.1392
haproxy / haproxy_enterprise = 2.6r1-1.0.0-296.1416
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1416
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1474
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1487
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1511
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1542
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1557
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1596
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1603
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1606
haproxy / haproxy_enterprise = 2.6r1-1.0.0-299.1618
haproxy / haproxy_enterprise = 2.6r1-1.0.0-300.1666
haproxy / haproxy_enterprise = 2.6r1-1.0.0-301.1666
haproxy / haproxy_enterprise = 2.8r1-1.0.0-302.234
haproxy / haproxy_enterprise = 2.8r1-1.0.0-304.266
haproxy / haproxy_enterprise = 2.8r1-1.0.0-305.279
haproxy / haproxy_enterprise = 2.8r1-1.0.0-305.285
haproxy / haproxy_enterprise = 2.8r1-1.0.0-306.288
haproxy / haproxy_enterprise = 2.8r1-1.0.0-306.289
haproxy / haproxy_enterprise = 2.8r1-1.0.0-307.317
haproxy / haproxy_enterprise = 2.8r1-1.0.0-310.350
haproxy / haproxy_enterprise = 2.8r1-1.0.0-310.364
haproxy / haproxy_enterprise = 2.8r1-1.0.0-310.373
haproxy / haproxy_enterprise = 2.8r1-1.0.0-310.374
haproxy / haproxy_enterprise = 2.8r1-1.0.0-310.418
haproxy / haproxy_enterprise = 2.8r1-1.0.0-310.422
haproxy / haproxy_enterprise = 2.8r1-1.0.0-310.424
haproxy / haproxy_enterprise = 2.8r1-1.0.0-311.449
haproxy / haproxy_enterprise = 2.8r1-1.0.0-311.452
haproxy / haproxy_enterprise = 2.8r1-1.0.0-311.453
haproxy / haproxy_enterprise = 2.8r1-1.0.0-312.592
haproxy / haproxy_enterprise = 2.8r1-1.0.0-312.613
haproxy / haproxy_enterprise = 2.8r1-1.0.0-317.613
haproxy / haproxy_enterprise = 2.8r1-1.0.0-318.674
haproxy / haproxy_enterprise = 2.8r1-1.0.0-319.699
haproxy / haproxy_enterprise = 2.8r1-1.0.0-319.723
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.750
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.761
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.770
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.780
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.781
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.783
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.831
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.851
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.853
haproxy / haproxy_enterprise = 2.8r1-1.0.0-320.895
haproxy / haproxy_enterprise = 2.8r1-1.0.0-321.895
haproxy / haproxy_enterprise = 2.8r1-1.0.0-321.901
haproxy / haproxy_enterprise = 2.8r1-1.0.0-321.919
haproxy / haproxy_enterprise = 2.8r1-1.0.0-321.931
haproxy / haproxy_enterprise = 2.8r1-1.0.0-321.934
haproxy / haproxy_enterprise = 2.8r1-1.0.0-321.937
haproxy / haproxy_enterprise = 2.8r1-1.0.0-322.942
haproxy / haproxy_enterprise = 2.8r1-1.0.0-324.1030
haproxy / haproxy_enterprise = 2.8r1-1.0.0-324.1071
haproxy / haproxy_enterprise = 2.8r1-1.0.0-324.1072
haproxy / haproxy_enterprise = 2.8r1-1.0.0-324.947
haproxy / haproxy_enterprise = 2.8r1-1.0.0-326.1073
haproxy / haproxy_enterprise = 3.0r1-1.0.0-337.363
haproxy / haproxy_enterprise = 3.0r1-1.0.0-337.390
haproxy / haproxy_enterprise = 3.0r1-1.0.0-337.394
haproxy / haproxy_enterprise = 3.0r1-1.0.0-339.395
haproxy / haproxy_enterprise = 3.0r1-1.0.0-339.405
haproxy / haproxy_enterprise = 3.0r1-1.0.0-339.415
haproxy / haproxy_enterprise = 3.0r1-1.0.0-339.455
haproxy / haproxy_enterprise = 3.0r1-1.0.0-339.466
haproxy / haproxy_enterprise = 3.0r1-1.0.0-339.471
haproxy / haproxy_enterprise = 3.0r1-1.0.0-341.475
haproxy / haproxy_enterprise = 3.0r1-1.0.0-342.482
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.495
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.503
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.561
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.564
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.591
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.608
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.641
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.655
haproxy / haproxy_enterprise = 3.0r1-1.0.0-344.672
haproxy / haproxy_enterprise = 3.0r1-1.0.0-345.673
haproxy / haproxy_enterprise = 3.0r1-1.0.0-346.792
haproxy / haproxy_enterprise = 3.1r1-1.0.0-345.233
haproxy / haproxy_enterprise = 3.1r1-1.0.0-346.274
haproxy / haproxy_enterprise = 3.1r1-1.0.0-346.287
haproxy / haproxy_enterprise = 3.1r1-1.0.0-347.299
haproxy / haproxy_enterprise = 3.1r1-1.0.0-347.338
haproxy / haproxy_enterprise = 3.1r1-1.0.0-347.362
haproxy / haproxy_enterprise = 3.1r1-1.0.0-347.405
haproxy / haproxy_enterprise = 3.1r1-1.0.0-347.419
haproxy / haproxy_enterprise = 3.1r1-1.0.0-347.431
haproxy / haproxy_enterprise = 3.1r1-1.0.0-347.449
haproxy / haproxy_enterprise = 3.1r1-1.0.0-348.519

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.