CVE-2024-49214
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
Published 2024-10-14. Last modified 2026-06-17.