Vulnerability record · CVE-2020-11100 · published 2 April 2020
CVE-2020-11100: HAProxy HPACK decoder heap out-of-bounds write
Haproxy · Haproxy
The HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4 contains an out-of-bounds write in hpack_dht_insert in hpack-tbl.c. A crafted HTTP/2 request lets a remote attacker write arbitrary bytes around a location on the heap, which can corrupt memory and potentially lead to remote code execution. Because HAProxy is commonly deployed as an internet-facing load balancer or reverse proxy, this flaw sits directly on the request path.
Description
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, low privileges and potential code execution, plus a very high EPSS score, though no confirmed KEV or in-the-wild exploitation is recorded.
What it is
The HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4 contains an out-of-bounds write in hpack_dht_insert in hpack-tbl.c. A crafted HTTP/2 request lets a remote attacker write arbitrary bytes around a location on the heap, which can corrupt memory and potentially lead to remote code execution. Because HAProxy is commonly deployed as an internet-facing load balancer or reverse proxy, this flaw sits directly on the request path.
Impact
An attacker can corrupt heap memory with attacker-controlled bytes, potentially achieving remote code execution in the HAProxy process. Even without code execution, the write can crash or destabilize the proxy, disrupting all traffic it fronts.
Attack surface
Reached remotely over the network by sending a crafted HTTP/2 request to an affected HAProxy instance; the CVSS vector indicates low privileges (PR:L) and no user interaction (UI:N). No local access is required, but the attacker must be able to deliver HTTP/2 traffic to the proxy.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.60727, 99.1st percentile), and references include a Packet Storm exploit write-up, indicating public technical detail exists, but the record does not confirm active in-the-wild exploitation.
What to do
- Upgrade HAProxy to 2.1.4 or later, or to the patched release for your branch, as the primary fix.
- Apply vendor security updates for Debian, Ubuntu, Red Hat/OpenShift, Fedora, openSUSE and Gentoo packages where HAProxy is bundled.
- If immediate patching is not possible, restrict or disable HTTP/2 on internet-facing HAProxy listeners and terminate HTTP/2 elsewhere.
- Limit exposure of HAProxy management and proxy endpoints to trusted networks and monitor for anomalous HTTP/2 request patterns.
- Verify the deployed HAProxy version after patching, since distributions backport fixes without changing the upstream version string.
Detection
- Monitor HAProxy logs and system logs for crashes, segfaults or abnormal process restarts that could indicate heap corruption.
- Inspect HTTP/2 traffic for malformed or oversized HPACK header blocks targeting the proxy.
- Track HAProxy process memory behavior and core dumps for signs of out-of-bounds writes.
- Audit deployed HAProxy versions against the fixed 2.1.4 baseline and vendor advisories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11100 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11100), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.