Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38439
HistoryDec 13, 2022 - 1:15 a.m.

Denial Of Service (DoS)

2022-12-1301:15:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
denial of service
netty-codec-haproxy
stackoverflowerror
haproxymessage.java
tlv
application crash
infinite recursion

EPSS

0.002

Percentile

56.3%

netty-codec-haproxy is vulnerable to Denial Of Service (DoS). The vulnerability is due to a StackOverflowError in the HAProxyMessage.java as it does not properly limit the maximum nesting of TLV, allowing an attacker to cause an application crash via infinite recursion by passing a maliciously crafted message.