CVE-2019-19330: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 19.04 only; version 19.10 only
  • Debian Debian Linux: version 10.0 only
  • Haproxy Haproxy: before 2.0.10 (fixed in 2.0.10)

Published 2019-11-27. Last modified 2026-06-17.