Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.77% | — | HaproxyAI | 13/9/2026 | 22/9/2026 | An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused… | |
| Analizada | Media (4.8) | 0.48% | — | HaproxyHaproxy AlohaHaproxy Enterprise | 20/7/2026 | 25/8/2026 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. | |
| Analizada | Baja (3.7) | 0.55% | — | HaproxyHaproxy AlohaHaproxy Enterprise | 20/7/2026 | 25/8/2026 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. | |
| Analizada | Alta (8.7) | 0.48% | — | Haproxy | 18/6/2026 | 14/7/2026 | HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to… | |
| Analizada | Crítica (9) | 0.58% | — | Haproxy | 18/6/2026 | 14/7/2026 | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and… | |
| Aplazada | Alta (8.1) | 0.49% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring… | |
| Aplazada | Alta (8.3) | 0.40% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches. | |
| Aplazada | Media (6.1) | 0.26% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via… | |
| Aplazada | Alta (8.1) | 0.47% | — | HaproxyAINginxAIApacheAIKeepalivedAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its if/elif/elif/else… | |
| Aplazada | Alta (8.8) | 0.52% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q {cfg}"). configver… | |
| Aplazada | Media (4.3) | 0.29% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization check. Any authenticated user — even a guest in an unrelated group —… | |
| Aplazada | Media (6.5) | 0.37% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the URL path component verbatim into requests.get(f'http://{server_ip}:{agent_port}/...'). The path component is… | |
| Aplazada | Media (6.1) | 0.25% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw HTML by string concatenation with no escaping. The frontend… | |
| Aplazada | Media (4.9) | 0.40% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path parameter is taken verbatim — no checkAjaxInput, no LDAP escape — and… | |
| Aplazada | Crítica (9.9) | 0.79% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that is not validated, not escaped,… | |
| Aplazada | Crítica (9.9) | 0.59% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(...) as the destination path. The… | |
| Aplazada | Crítica (9.9) | 0.45% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip,… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target check_id belongs to… | |
| Aplazada | Alta (8.5) | 0.35% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — no role check, no group ownership check on the server_ip form field.… | |
| Analizada | Media (5.8) | 0.58% | — | Haproxy | 13/4/2026 | 29/6/2026 | An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request… | |
| Analizada | Alta (7.5) | 0.69% | — | Haproxy Aloha ApplianceHaproxyHaproxy EnterpriseHaproxy Kubernetes Ingress Controller | 19/11/2025 | 17/6/2026 | Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests. | |
| Aplazada | Media (6.4) | 0.26% | — | Haproxy Kubernetes Ingress ControllerAI | 8/10/2025 | 17/6/2026 | HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are… | |
| Aplazada | Media (6.8) | 0.75% | — | HaproxyAI | 9/4/2025 | 17/6/2026 | HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one. | |
| Aplazada | Media (5.3) | 1.0% | — | HaproxyAI | 28/11/2024 | 17/6/2026 | Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information. | |
| Aplazada | Media (5.3) | 0.52% | — | HaproxyAI | 14/10/2024 | 17/6/2026 | QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality. |