CVE-2024-45506
ENISA EUVD: EUVD-2024-41515 ↗
✓ Confirmed 0-Day
Triaged: March 5, 2026
1 article
Published: 2024-09-04
EPSS Score
Source: FIRST.org · 2026-05-23
1.49%
probability
This CVE has a 1.49% probability
of being exploited in the next 30 days.
0%
Top 81.3th percentile of all CVEs
100%
CVSS v3.1
Source: VulnerabilityLookup (CIRCL)7.5
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
VulnerabilityLookup (CNA)HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
Affected Products
n/a
n/a
Attack Intelligence
Signal Intelligence
Confidence
78%
EPSS
1.49%
CVSS v3.1
7.5
Mentions
1
Last Seen
Feb 18, 2026
CNA Information
CNA Assigner
mitre
Analyst Note
CVE description explicitly states 'as exploited in the wild in 2024' and CVE was published 2024-09-04. The 2024 publication year combined with explicit documentation of wild exploitation in the same year indicates exploitation occurred contemporaneously with or before patch release, meeting zero-day criteria.
Triage Info
Decided atMar 05, 2026
Published DateSep 04, 2024