VDB
DEBIAN-CVE-2019-19330
DEBIAN-CVE-2019-19330
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | haproxy | 0, 0, 0 |
| Debian:11 | haproxy | 0, 0, 0 |
| Debian:12 | haproxy | 0, 0, 0 |
| Debian:13 | haproxy | 0, 0, 0 |
Timeline
- Nov 27, 2019 CVE Published
- Apr 28, 2026 CVE Updated