Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
haproxy-debuginfo Red Hat / RHEL
haproxy-debugsource Red Hat / RHEL
registry.redhat.io/rhceph/grafana Red Hat / RHEL
Fixed in: rhel9@sha256:1d1953d6ed948441a2d441b5050b6bc4f3b8ac66e1724bb0eb2fae2cb56267d3_arm64 RHSA-2025:22548 Fixed in: rhel9@sha256:b5f1c693c7a01a39ac46a2a35d61f786d3f79deb62fe55e7fdac1ba627fb6dc9_ppc64le RHSA-2025:22548 Fixed in: rhel9@sha256:9ddb4ab1d3b584f33d6ae2756b13f74e50b5a55630b3000df963595b36ef1b61_amd64 RHSA-2025:22548 Fixed in: rhel9@sha256:97950d588d5b033ab672114c0f5cd96ebd39246795511e7fe2fd1277aa94a1c8_s390x RHSA-2025:22548 registry.redhat.io/rhceph/grafana Rocky
Fixed in: rhel9@sha256:b5f1c693c7a01a39ac46a2a35d61f786d3f79deb62fe55e7fdac1ba627fb6dc9_ppc64le RHSA-2025:22548 Fixed in: rhel9@sha256:1d1953d6ed948441a2d441b5050b6bc4f3b8ac66e1724bb0eb2fae2cb56267d3_arm64 RHSA-2025:22548 Fixed in: rhel9@sha256:97950d588d5b033ab672114c0f5cd96ebd39246795511e7fe2fd1277aa94a1c8_s390x RHSA-2025:22548 Fixed in: rhel9@sha256:9ddb4ab1d3b584f33d6ae2756b13f74e50b5a55630b3000df963595b36ef1b61_amd64 RHSA-2025:22548 registry.redhat.io/rhceph/rhceph Red Hat / RHEL
Fixed in: 8-rhel9@sha256:75e6643866fa05fce50284a164d48533259c91be3fcac85556844a67e25887e9_s390x RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:eef8a3d296b098659dfdfb64a9e89b9f955015e29d69976eb3f9feffc9304a34_s390x RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:75d9ee1d25f4770172b0243aab13a13895f1be84fa0695efdad4a33428594843_ppc64le RHSA-2025:22548 Fixed in: 8-rhel9@sha256:69c4edadc3bfd45dd982764b7f9d9a0f3a6d74d26a0443796aaa4a65455c62d1_arm64 RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:aea85ef95ff6a40839955c80a64dad0c4ff8bcfd1f4b0b15262caee21ee26ef3_arm64 RHSA-2025:22548 Fixed in: 8-rhel9@sha256:04a48d31f7336e0d5958eed1ddb1a117148f791baccef4e6e08943181e6794c8_amd64 RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:2fbfd8ab9adf2a0ee77b5ef5c07be5787a6820ef40b5eef3a27628d94bf188a6_amd64 RHSA-2025:22548 Fixed in: 8-rhel9@sha256:08f8552a0a56a47ab606bed47b603e3d2aedaa389d4a5df4dbfa06acee85c0c0_ppc64le RHSA-2025:22548 registry.redhat.io/rhceph/rhceph Rocky
Fixed in: 8-rhel9@sha256:69c4edadc3bfd45dd982764b7f9d9a0f3a6d74d26a0443796aaa4a65455c62d1_arm64 RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:aea85ef95ff6a40839955c80a64dad0c4ff8bcfd1f4b0b15262caee21ee26ef3_arm64 RHSA-2025:22548 Fixed in: 8-rhel9@sha256:04a48d31f7336e0d5958eed1ddb1a117148f791baccef4e6e08943181e6794c8_amd64 RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:2fbfd8ab9adf2a0ee77b5ef5c07be5787a6820ef40b5eef3a27628d94bf188a6_amd64 RHSA-2025:22548 Fixed in: 8-rhel9@sha256:08f8552a0a56a47ab606bed47b603e3d2aedaa389d4a5df4dbfa06acee85c0c0_ppc64le RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:75d9ee1d25f4770172b0243aab13a13895f1be84fa0695efdad4a33428594843_ppc64le RHSA-2025:22548 Fixed in: 8-rhel9@sha256:75e6643866fa05fce50284a164d48533259c91be3fcac85556844a67e25887e9_s390x RHSA-2025:22548 Fixed in: haproxy-rhel9@sha256:eef8a3d296b098659dfdfb64a9e89b9f955015e29d69976eb3f9feffc9304a34_s390x RHSA-2025:22548 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Impact
Confidentiality None
Integrity None
Availability High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U
0.52% probability of exploitation in 30 days
41st percentile
Moderate risk: more likely to be exploited than 41% of all known CVEs.
Other CWE-407 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2025-11230 Markdown
[](https://tridentstack.com/cve/CVE-2025-11230)HTML
<a href="https://tridentstack.com/cve/CVE-2025-11230"><img src="https://tridentstack.com/cve/badge/CVE-2025-11230.svg" alt="CVE-2025-11230"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-12-19.