VDB

DEBIAN-CVE-2019-19330

DEBIAN-CVE-2019-19330 PUBLISHED CVSS 9.800000190734863 CRITICAL

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:14haproxy0, 0, 0
Debian:11haproxy0, 0, 0
Debian:12haproxy0, 0, 0
Debian:13haproxy0, 0, 0

Timeline

  • Nov 27, 2019 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›