Vulnerability Description
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haproxy | Aloha Appliance | >= 14.5.0, < 14.5.33 |
| Haproxy | Haproxy | >= 2.4.0, < 2.4.30 |
| Haproxy | Haproxy Enterprise | 2.4r1 |
| Haproxy | Kubernetes Ingress Controller | < 1.9.14-ee7 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-11230?
CVE-2025-11230 is a vulnerability with a CVSS score of 7.5 (HIGH). Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
How severe is CVE-2025-11230?
CVE-2025-11230 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11230?
Check the references section above for vendor advisories and patch information. Affected products include: Haproxy Aloha Appliance, Haproxy Haproxy, Haproxy Haproxy Enterprise, Haproxy Kubernetes Ingress Controller.