CVE-2023-0836

Publication date 27 March 2023

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

Status

Package Ubuntu Release Status
haproxy 23.04 lunar
Not affected
22.10 kinetic
Fixed 2.4.18-1ubuntu1.3
22.04 LTS jammy
Fixed 2.4.18-0ubuntu1.3
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
14.04 LTS trusty Ignored end of standard support

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.5 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities