Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
Conclusion & alert: CVE-2025-11230 is rated Moderate Risk (52.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.47%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-29 | 0.41% | 0.47% | +0.06% |
| 2 | 2026-03-21 | 0.27% | 0.41% | +0.14% |
| 3 | 2026-03-01 | — | 0.27% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-11230: 1 source package rows (haproxy); 30 state rows across 5 repos (3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 0, open 30. | https://security.alpinelinux.org/vuln/CVE-2025-11230 |
debian
|
unimportant | CVE-2025-11230 unimportant priority: Debian including 1 source packages (haproxy), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-11230 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-11230 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2025-11230/ |
ubuntu
|
medium | CVE-2025-11230 medium priority: Ubuntu including 1 source packages (haproxy), 7 status rows across 7 suites (bionic, focal, jammy, noble, plucky, upstream, xenial): not-affected 3, released 3, needs-triage 1. | https://ubuntu.com/security/CVE-2025-11230 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| haproxy | aloha_appliance | >= 14.5.0, < 14.5.33 | cpe:2.3:a:haproxy:aloha_appliance:*:*:*:*:*:*:*:* |
| haproxy | aloha_appliance | >= 15.5.0, < 15.5.28 | cpe:2.3:a:haproxy:aloha_appliance:*:*:*:*:*:*:*:* |
| haproxy | aloha_appliance | >= 16.5.0, < 16.5.19 | cpe:2.3:a:haproxy:aloha_appliance:*:*:*:*:*:*:*:* |
| haproxy | aloha_appliance | >= 17.0.0, < 17.0.7 | cpe:2.3:a:haproxy:aloha_appliance:*:*:*:*:*:*:*:* |
| haproxy | haproxy | >= 2.4.0, < 2.4.30 | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* |
| haproxy | haproxy | >= 2.6.0, < 2.6.23 | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* |
| haproxy | haproxy | >= 2.8.0, < 2.8.16 | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* |
| haproxy | haproxy | >= 3.0.0, < 3.0.12 | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* |
| haproxy | haproxy | >= 3.1.0, < 3.1.9 | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* |
| haproxy | haproxy | >= 3.2.0, < 3.2.6 | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-253.271:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-254.271:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-259.342:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-263.343:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-264.356:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.356:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.373:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.459:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.464:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.477:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.499:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.553:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.560:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.564:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-268.596:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-269.596:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-269.599:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-270.616:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-271.673:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-271.677:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-272.683:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-272.686:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-272.728:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-274.752:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-276.752:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-277.814:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-277.831:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-278.838:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.852:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.859:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.877:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.911:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.940:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.952:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.953:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-279.956:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-280.956:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-282.998:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-282.999:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-284.999:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-285.1010:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-286.1064:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-286.1068:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-286.1089:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-286.1094:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-288.1094:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-288.1158:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-288.1167:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-288.1189:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-289.1189:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-290.1239:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-291.1246:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-292.1293:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-294.1346:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-294.1364:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-294.1376:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-294.1377:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.4r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.4r1:1.0.0-294.1442:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-281.466:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-282.561:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-283.562:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-283.565:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-283.616:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-283.632:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-283.633:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-283.636:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-284.636:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-285.726:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-285.727:*:*:*:*:*:* |
| haproxy | haproxy_enterprise | 2.6r1 | cpe:2.3:a:haproxy:haproxy_enterprise:2.6r1:1.0.0-287.727:*:*:*:*:*:* |