Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Haproxy
Haproxy haproxy
Vendors & Products Haproxy
Haproxy haproxy

Wed, 19 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in haproxy. A stemming from an inefficient algorithmic complexity issue within its bundled mjson parsing library. This vulnerability is triggered when haproxy is configured to analyze JSON content, such as with the json_query or jwt_payload_query function Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
Title haproxy: denial of service vulnerability in HAProxy mjson library Denial of service vulnerability in HAProxy mjson library
References

Fri, 07 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in haproxy. A stemming from an inefficient algorithmic complexity issue within its bundled mjson parsing library. This vulnerability is triggered when haproxy is configured to analyze JSON content, such as with the json_query or jwt_payload_query function
Title haproxy: denial of service vulnerability in HAProxy mjson library
Weaknesses CWE-407
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2025-11-19T09:28:39.750Z

Updated: 2025-11-19T17:09:15.642Z

Reserved: 2025-10-01T13:10:26.249Z

Link: CVE-2025-11230

cve-icon Vulnrichment

Updated: 2025-11-19T17:09:02.607Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-19T10:15:45.020

Modified: 2025-11-19T19:14:59.327

Link: CVE-2025-11230

cve-icon Redhat

Severity : Important

Publid Date: 2025-10-03T00:00:00Z

Links: CVE-2025-11230 - Bugzilla