[Git][security-tracker-team/security-tracker][master] Add CVE-2025-11230/haproxy

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Oct 3 13:03:31 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b604e01b by Salvatore Bonaccorso at 2025-10-03T14:03:04+02:00
Add CVE-2025-11230/haproxy

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,9 @@
+CVE-2025-11230 [BUG/CRITICAL: mjson: fix possible DoS when parsing numbers]
+	- haproxy <unfixed>
+	[bullseye] - haproxy <not-affected> (Vulnerable code introduced later)
+	NOTE: Introduced with: https://github.com/haproxy/haproxy/commit/41007a6835fe29f865e01d8fbeb96114c0d01828 (v2.4-dev17)
+	NOTE: Fixed by: https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=6fd1287526eae1b31329997a2df29c9fb564a8e8 (v3.2.6)
+	NOTE: Fixed by: https://github.com/haproxy/haproxy/commit/06675db4bf234ed17e14305f1d59259d2fe78b06 (v3.3-dev9)
 CVE-2025-61847
 	REJECTED
 CVE-2025-61671



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b604e01bc32b38a05eb354d53d539345e55c2371

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b604e01bc32b38a05eb354d53d539345e55c2371
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251003/fe7eb3d4/attachment.htm>


More information about the debian-security-tracker-commits mailing list