For more information on the release, see:
- https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=c3bf1ac6709072bf9984c829c3badda5a4e8fa7e
This fixes the following vulnerability:
- CVE-2025-11230:
Inefficient algorithm complexity in mjson in HAProxy allows remote
attackers to cause a denial of service via specially crafted JSON
requests.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2025-11230
- https://www.haproxy.com/blog/october-2025-cve-2025-11230-haproxy-mjson-library-denial-of-service-vulnerability
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit d94d4ff0a6)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>