peter bassill · operator
$ cve CVE-2019-19330 JSON

CVE-2019-19330

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.03% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploitnone known
Published2019-11-27
Last modified2026-06-17

Affected (3)

VendorProduct
canonicalubuntu linux
debiandebian linux
haproxyhaproxy

References

→ the Explorer  ·  watch your stack  ·  NVD