CVE-2025-11230: Haproxy Aloha Appliance
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
Affected products
- Haproxy Aloha Appliance: from 14.5.0, before 14.5.33 (fixed in 14.5.33); from 15.5.0, before 15.5.28 (fixed in 15.5.28); from 16.5.0, before 16.5.19 (fixed in 16.5.19); from 17.0.0, before 17.0.7 (fixed in 17.0.7)
- Haproxy Haproxy: from 2.4.0, before 2.4.30 (fixed in 2.4.30); from 2.6.0, before 2.6.23 (fixed in 2.6.23); from 2.8.0, before 2.8.16 (fixed in 2.8.16); from 3.0.0, before 3.0.12 (fixed in 3.0.12); from 3.1.0, before 3.1.9 (fixed in 3.1.9); from 3.2.0, before 3.2.6 (fixed in 3.2.6)
- Haproxy Haproxy Enterprise: version 2.4r1 only; version 2.6r1 only; version 2.8r1 only; version 3.0r1 only; version 3.1r1 only
- Haproxy Kubernetes Ingress Controller: before 1.9.14-ee7 (fixed in 1.9.14-ee7); before 3.1.12 (fixed in 3.1.12); from 1.10.10-ee1, before 1.11.12-ee10 (fixed in 1.11.12-ee10); from 3.0.0-ee1, before 3.0.15-ee4 (fixed in 3.0.15-ee4)
Published 2025-11-19. Last modified 2026-06-17.