Heap-Based Buffer Overflow Vulnerability in HAProxy by HAProxy Technologies
CVE-2025-32464
6.8MEDIUM
What is CVE-2025-32464?
A buffer overflow vulnerability exists in HAProxy versions 2.2 through 3.1.6 due to mishandling of pattern replacements in certain configurations. This issue can result in a heap-based buffer overflow when multiple short patterns are replaced with a longer one, potentially allowing attackers to execute arbitrary code.
Affected Version(s)
HAProxy 2.2 <= 3.1.6