2026-09-18BUG/MEDIUM: limits: properly account for global.maxpipes in compute_ideal_maxconn() 2026-09-18BUG/MEDIUM: htx: Reserve a block descriptor for zero-sized blocks 2026-09-18BUG/MINOR: sample: reject a \0 byte in url_dec, json_query and jwt_*_query 2026-09-18BUG/MINOR: ssl: Fix leak of ca_list in cafile_entry 2026-09-18BUG/MEDIUM: http_act: fix normalize-uri normalizer selection with a condition 2026-09-18BUG/MEDIUM: map: do not overwrite the fetch context in pat_match_regm() 2026-09-18BUG/MINOR: ssl: don't pass the address of a size_t as an int* to OpenSSL 2026-09-18BUG/MINOR: h3: only increment frame type counter on new header 2026-09-18BUG/MINOR: h3: handle empty HEADERS frame as specified 2026-09-18BUG/MEDIUM: h3: do not block FIN on empty DATA frame 2026-09-18BUG/MINOR: hlua: Always return nil if there is no data to dup for HTTP messages 2026-09-18BUG/MEDIUM: hlua: Never release a cosocket applet from the GC 2026-09-18BUG/MINOR: qpack: accept a Required Insert Count which cannot be reached 2026-09-18BUG/MINOR: qpack: encoder and decoder stream data is never consumed 2026-09-18BUG/MINOR: resolvers: classify empty truncated responses 2026-09-18BUG/MINOR: quic: late packets of the first key phase are dropped 2026-09-18BUG/MEDIUM: quic: crash on key update phase change after a failed one 2026-09-18BUG/MINOR: payload: bound ClientHello extension lists by the extension length 2026-08-26BUG/MINOR: flt-http-comp: Don't read next block to detect end of data 2026-08-26BUG/MINOR: fcgi-app: allow explicit filter declaration with non-cache/non-compression filters 2026-08-26BUG/MEDIUM: cache: ignore cache on redundant origin/referer 2026-08-26BUG/MINOR: auth: free user groups on error paths in userlist_postinit() 2026-08-26BUG/MINOR: tools: fix memory leak in env_expand() error path 2026-08-26BUG/MINOR: http-act: set-status() must check the response message, not the request 2026-08-26BUG/MINOR: http-fetch: make http_first_req() check for HTTP first 2026-08-26BUG/MINOR: ot: removed dead code in flt_ot_parse_cfg_str() 2026-08-26BUG/MINOR: config: Check buffer pool creation for failures 2026-08-26BUG/MINOR: wurfl: fix memory leak of information list and patch strings at deinit 2026-08-26BUG/MEDIUM: mux-fcgi: check the room left before appending the index 2026-08-26BUG/MINOR: resolvers: accept fields at the response boundary 2026-08-26BUG/MEDIUM: ssl: isolate TLS session resumption per authentication policy 2026-08-26BUG/MINOR: ssl: isolate TLS session resumption per crt-list filter 2026-08-26BUG/MEDIUM: ssl: isolate TLS session resumption per X509 server certificate 2026-08-26BUG/MINOR: ssl: apply tune.ssl.lifetime to TLS1.3 sessions on BoringSSL/AWS-LC 2026-08-26BUG/MINOR: ssl: release the previous client cert reference at depth > 0 2026-08-26BUG/MINOR: conn: Do not check 'sess_el' list on frontend connections in __trace_enabled 2026-08-26BUG/MINOR: qpack: missing shift count check in qpack_get_varint() (UB) 2026-08-26BUG/MINOR: spoe: check snprintf() return value in spoe_set_var/spoe_unset_var 2026-08-26BUG/MINOR: payload: fix handshake length off-by-4 in ssl_hello_sni/alpn 2026-08-26BUG/MEDIUM: http: fix authority parsing for absolute-form URI with empty path 2026-08-26BUG/MEDIUM: lua: resume Channel:send() from the unsent part of the string 2026-08-26BUG/MINOR: mux-h2: strip the userinfo when deriving :authority for a server 2026-08-26BUG/MINOR: lb-chash: bound the walk when the saved cursor changed tree 2026-08-26BUG/MINOR: connection: reserve the whole CRC32C TLV before saving its pointer 2026-08-26BUG/MINOR: ssl: reject server certificate names containing a NUL byte 2026-08-26BUG/MINOR: mux-fcgi: sanitize the STDERR records before logging them 2026-08-26BUG/MEDIUM: http-ana: check the cookie rewrite result before moving the offsets 2026-08-26BUG/MEDIUM: sock: bound the recvmsg() length when receiving old sockets 2026-08-26BUG/MINOR: mux-fcgi: don't call fcgi_strm_destroy() on a NULL stream 2026-08-26BUG/MINOR: hlua: use a local buffer to format the socket addresses 2026-08-26BUG/MEDIUM: hpack: encode long methods and schemes using the long form 2026-08-26BUG/MINOR: server: check strdup return value on server ID 2026-07-29BUG/MEDIUM: sample: reject the deprecated protobuf group wire types 2026-07-29BUG/MEDIUM: peers: check the available room before encoding dict values 2026-07-29BUG/MINOR: slz: avoid undefined shifts when building the word byte by byte 2026-07-29BUG/MINOR: slz: fix the adler32 accumulators signedness on 32-bit 2026-07-29BUG/MINOR: slz: do not append a block to an already finished stream 2026-07-29BUG/MEDIUM: slz: bound the bits wasted by the 9-bit literals 2026-07-29BUG/MINOR: slz: use the exact switch cost for the last literals of a block 2026-07-29BUG/MINOR: slz: do not read past the end of the input around the match loop 2026-07-29BUG/MINOR: htx: Transfer HTX_FL_EOM flag on success in htx_append_msg() 2026-07-29BUG/MINOR: htx: Perform raw copy for messages of same size in htx_copy_msg() 2026-07-29BUG/MINOR: http-htx: check the strdup() of the "lf-string" http reply argument 2026-07-29BUG/MINOR: http-act: reject a negative capture id in the capture actions 2026-07-29BUG/MINOR: http-act: restore the response buffer state in the early-hint action 2026-07-29BUG/MINOR: http-act: fix a double free of the map reference on a parsing error 2026-07-29BUG/MINOR: http-act: fix a double free of the regex on a rule parsing error 2026-07-29BUG/MINOR: http-ana: fix a one-byte over-read in the client-side cookie parser 2026-07-29BUG/MINOR: h2: don't use a block pointer to roll back a partial HTX conversion 2026-07-29BUG/MINOR: http-htx: check the trash allocation in http_scheme_based_normalize() 2026-07-29BUG/MEDIUM: http-fetch: reject a negative capture id in capture.{req,res}.hdr 2026-07-29BUG/MEDIUM: http-fetch: don't parse a non-HTTP check buffer as an HTX message 2026-07-29BUG/MINOR: http-htx: fix the length moved when removing a header value 2026-07-22BUG/MEDIUM: sample: Adjust sample size capacity after pointer shift for ltrim() 2026-07-22BUG/MINOR: mux-h1: Don't delay send if message with c-l was fully sent 2026-07-22BUG/MEDIUM: protobuf: fix nested path bypass in field lookup 2026-07-22BUG/MEDIUM: protobuf: adjust sample size capacity after pointer shift 2026-07-22BUG/MEDIUM: ssl-gencert: Don't forget to free memory when done 2026-07-22BUG/MEDIUM: stats: Ensure that Origin is valid on POSTs 2026-07-22BUG/MEDIUM: stats: subject "stats admin" accesses to "stats scope" filtering 2026-07-22BUG/MINOR: http-conv: Make url-dec failed if no space for trailing null byte 2026-07-22BUG/MINOR: sample: Fix a possible underflow on be2hex for large chunk size 2026-07-02BUG/MINOR: http-htx: Don't by-pass HTX API when merging cookie values 2026-07-02BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error 2026-07-02BUG/MINOR: tools: fix invalid character detection in strl2ic() 2026-07-02BUG/MINOR: sample: set SMP_F_CONST on srv_name fetch 2026-06-26BUG/MEDIUM: mux-quic: Drain the given amount of data in qcs_http_reset_buf() 2026-06-26BUG/MEDIUM: mux-h2: Truly drain outgoing HTX data when the stream is closed 2026-06-26BUG/MEDIUM: mux-fcgi: Truly drain outgoing HTX data when the stream is closed 2026-06-26BUG/MINOR: server: fix add server with consistent hash balancing 2026-06-26BUG/MEDIUM: ssl: Don't free the early data buffer too early 2026-06-26BUG/MINOR: mux-h1: Properly resolve file path for 'h1-case-adjust-file' 2026-06-26BUG/MINOR: mux_h1: handle a possible strdup() failure 2026-06-26BUG/MEDIUM: http-ana: Don't ignore L7 retry errors 2026-06-26BUG/MEDIUM: check: Skip tcpcheck post-config for external checks 2026-06-26BUG/MEDIUM: mux-h1: Dup connection/upgrade value to parse it when making headers 2026-06-26BUG/MINOR: cache: Fix copy of value when parsing maxage 2026-06-26BUG/MINOR: qpack: fix huff_dec() error handling in qpack_decode_fs() 2026-06-26BUG/MINOR: qpack: fix sign bit mask in qpack_decode_fs_pfx() 2026-06-26BUG/MINOR: qpack: fix potential null-pointer dereference in qpack_dht_insert() 2026-06-26BUG/MINOR: qpack: Fix index calculation in debug functions 2026-06-26Revert "BUG/MEDIUM: dns: fix long loops in additional records parse on name failure" 2026-06-26BUG/MINOR: ssl-gencert: validate SNI characters to prevent SAN certificate injection 2026-06-26BUG/MINOR: mux-fcgi: Use relative offset to compute contig data in demux buf 2026-06-26BUG/MEDIUM: mux-fcgi: reject stream ID 0 for application records 2026-06-26BUG/MINOR: hlua: prevent Lua from passing CR/LF/NUL in HTTP headers 2026-06-26BUG/MEDIUM: auth: fix unconfigured password NULL deref 2026-06-26BUG/MINOR: addons/51d: NUL-terminate headers before passing them to Trie API 2026-06-26BUG/MINOR: ssl-hello: make use of the null-terminated servername 2026-06-26BUG/MINOR: payload: fix the handshake length bounds check smp_client_hello_parse() 2026-06-26BUG/MINOR: http-fetch: check against the whole token in get_http_auth() 2026-06-26BUG/MEDIUM: cache: always verify the primary hash in get_secondary_entry() 2026-06-26BUG/MINOR: sample: limit the be2hex converter's chunk size 2026-06-26BUG/MINOR: dict: fix refcount race on insert collision 2026-06-26BUG/MINOR: mux-h2: validate HEADERS frame length before reading stream dep 2026-06-26BUG/MINOR: resolvers: fix risk of appending garbage past the domain name 2026-06-26BUG/MINOR: resolvers: fix room for trailing zero in resolv_dn_label_to_str() 2026-06-26BUG/MEDIUM: log-forward: make sure the month is unsigned 2026-06-26BUG/MEDIUM: hlua: Fix integer underflow when receiving line from lua cosocket 2026-06-26BUG/MEDIUM: dict: hold lock while decrementing refcount in dict_entry_unref 2026-06-26BUG/MEDIUM: resolvers: Fix test on dn label size in resolv_dn_label_to_str() 2026-06-19BUG/MEDIUM: mux-fcgi: fix uint16_t overflow in drl += drp 2026-06-19BUG/MINOR: hpack-tbl: add missing NULL check after hpack_dht_defrag() 2026-05-21BUG/MEDIUM: server: Duplicate healthcheck's alpn inherited from default server 2026-05-21BUG/MINOR: h1: Don't mask websocket protocol if multiple protocols used 2026-05-21BUG/MEDIUM: h1: Skip all h2c values from Upgrade headers during parsing 2026-05-21BUG/MINOR: httpclient-cli: Destroy http-client context if failing to start it 2026-05-21BUG/MINOR: jwt: fix possible memory leak in convert_ecdsa_sig() error path 2026-05-21BUG/MINOR: resolvers: report the expression error in the do-resolve() action parser 2026-05-21BUG/MINOR: dns: fix dangling dgram pointer on dns_dgram_init() failure path 2026-05-21BUG/MEDIUM: dns: fix memory leak of sockaddr in dns_session_init() error path 2026-05-21BUG/MEDIUM: resolvers: fix name compression pointer validation in resolv_read_name() 2026-05-21BUG/MEDIUM: dns: fix long loops in additional records parse on name failure 2026-05-21BUG/MINOR: backend: correct parameter value validation in get_server_ph_post() 2026-05-21BUG/MEDIUM: dict: hold read lock while incrementing refcount in dict_insert 2026-05-11BUG/MINOR: cfgparse-listen: do not emit extraneous line in rule order warnings 2026-05-07BUG/MEDIUM: stick-table: properly check permissions on CLI's set/clear cmd 2026-05-07BUG/MEDIUM: mux-h2: fix the detection of the ext connect support 2026-05-07Revert "BUG/MINOR: mux-h2: condition the processing of 8441 extension to global setting" 2026-05-07Revert "BUG/MEDIUM: cli: fix master CLI connection slot leak on client disconnect" 2026-05-06BUG/MEDIUM: h1_htx: Remove reverved block on error during contig chunks parsing 2026-05-06BUG/MINOR: http-fetch: Fix http_auth_bearer() when custom header is used 2026-05-06BUG/MINOR: h2: only accept :protocol with extended CONNECT 2026-05-06BUG/MINOR: mux-h2: condition the processing of 8441 extension to global setting 2026-05-06BUG/MINOR: h2: add decoding for :protocol in traces 2026-05-05BUG/MINOR: tcpcheck: Properly report error for http health-checks 2026-05-04BUG/MEDIUM: cli: fix master CLI connection slot leak on client disconnect 2026-05-04BUG/MINOR: mworker/cli: check ci_insert() return value in pcli_parse_request() 2026-05-04BUG/MINOR: resolvers: Free opts on parse error in resolv_parse_do_resolve() 2026-05-04BUG/MINOR: resolvers: Free new requester on error when linking a resolution 2026-05-04BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in h2c_dec_hdrs() 2026-05-04BUG/MEDIUM: mux-h2: fix the body_len to check when parsing request trailers 2026-05-04BUG/MINOR: map: do not leak a map descriptor on load error 2026-05-04BUG/MINOR: hpack: validate idx > 0 in hpack_valid_idx() 2026-05-04BUG/MINOR: vars: only print first invalid char in fill_desc() 2026-05-04BUG/MINOR: vars: don't store the variable twice with set-var-fmt 2026-05-04BUG/MINOR: vars: make parse_store() return error on var_set() failure 2026-04-30BUG/MINOR: http-htx: Don't normalize emtpy path for OPTIONS requests 2026-04-29BUG/MEDIUM: mux-fcgi: Properly handle full buffer for FCGI_PARAM record 2026-04-29BUG/MINOR: payload: prevent integer overflow in distcc token parsing 2026-04-29BUG/MEDIUM: http-htx: Loop on full host value during scheme based normalization 2026-04-29BUG/MEDIUM: http-htx: Don't use data from HTX message to update authority 2026-04-29BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based normalization 2026-04-29BUG/MINOR: tools: my_memspn/my_memcspn wrong cast causing incorrect byte reading 2026-04-23BUG/MEDIUM: mux-h1: Force close mode for bodyless message announcing a C-L 2026-04-23BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well 2026-04-23BUG/MINOR: hlua: fix use-after-free of HTTP reason string 2026-04-23BUG/MEDIUM: mux-fcgi: prevent record-length truncation with large bufsize 2026-04-23BUG/MINOR: sample: fix info leak in regsub when exp_replace fails 2026-04-23BUG/MEDIUM: samples: Fix handling of SMP_T_METH samples 2026-04-23BUG/MINOR: spoe: fix pointer arithmetic overflow in spoe_decode_buffer() 2026-04-23BUG/MAJOR: slz: always make sure to limit fixed output to less than worst case literals 2026-04-23BUG/MINOR: peers: fix OOB heap write in dictionary cache update 2026-04-23BUG/MINOR: hlua: fix stack overflow in httpclient headers conversion 2026-04-23BUG: hlua: fix stack overflow in httpclient headers conversion 2026-04-23BUG/MEDIUM: jwt: fix heap overflow in ECDSA signature DER conversion 2026-04-23BUG/MEDIUM: payload: validate SNI name_len in req.ssl_sni 2026-04-23BUG/MINOR: cfgcond: fail cleanly on missing argument for "feature" 2026-04-23BUG/MINOR: cfgcond: always set the error string on openssl_version checks 2026-04-23BUG/MINOR: cfgcond: properly set the error pointer on evaluation error 2026-04-17BUG/MINOR: config: Properly test warnif_misplaced_* return values 2026-04-17BUG/MINOR: qpack: fix 62-bit overflow and 1-byte OOB reads in decoding 2026-04-17BUG/MINOR: sock: adjust accept() error messages for ENFILE and ENOMEM 2026-03-20BUG/MEDIUM: h3: reject unaligned frames except DATA 2026-03-20BUG/MAJOR: h3: check body size with content-length on empty FIN 2026-03-20BUG/MINOR: mux-h2: properly ignore R bit in WINDOW_UPDATE increments 2026-03-20BUG/MINOR: mux-h2: properly ignore R bit in GOAWAY stream ID 2026-03-20BUG/MEDIUM: peers: enforce check on incoming table key type 2026-03-20BUG/MINOR: mjson: make mystrtod() length-aware to prevent out-of-bounds reads 2026-03-20BUG/MINOR: stream: Fix crash in stream dump if the current rule has no keyword 2026-03-20BUG/MINOR: http-ana: Swap L7 buffer with request buffer by hand 2026-03-20BUG/MINOR: h2/h3: Never insert partial headers/trailers in an HTX message 2026-03-20BUG/MINOR: h2/h3: Only test number of trailers inserted in HTX message 2026-03-20BUG/MINOR: sockpair: set FD_CLOEXEC on fd received via SCM_RIGHTS 2026-03-20BUG/MINOR: mworker: fix typo &= instead of & in proc list serialization 2026-03-20BUG/MINOR: tcpcheck: Fix typo in error error message for `http-check expect` 2026-03-09BUG/MINOR: backend: Don't get proto to use for webscoket if there is no server 2026-03-09BUG/MINOR: ssl-sample: Fix sample_conv_sha2() by checking EVP_Digest* failures 2026-03-05BUG/MEDIUM: mux-fcgi: Use a safe loop to resume each stream eligible for sending 2026-03-05BUG/MAJOR: resolvers: Properly lowered the names found in DNS response 2026-03-05BUG/MINOR: resolvers: always normalize FQDN from response 2026-03-05BUG/MAJOR: fcgi: Fix param decoding by properly checking its size 2026-03-05BUG/MINOR: h1-htx: Be sure that H1 response version starts by "HTTP/" 2026-03-05BUG/MEDIUM: qpack: correctly deal with too large decoded numbers 2026-03-05BUG/MINOR: qpack: fix 1-byte OOB read in qpack_decode_fs_pfx() 2026-03-05BUG/MAJOR: qpack: unchecked length passed to huffman decoder 2026-03-05BUG/MEDIUM: hpack: correctly deal with too large decoded numbers 2025-10-14BUG/MINOR: sink: retry attempt for sft server may never occur 2025-10-10BUG/MINOR: ssl: always clear the remains of the first hello for the second one 2025-10-10BUG/MEDIUM: ssl: take care of second client hello 2025-10-02BUG/MINOR: h3: forbid 'Z' as well in header field names checks 2025-10-02BUG/MINOR: h2: forbid 'Z' as well in header field names checks 2025-10-02BUG/CRITICAL: mjson: fix possible DoS when parsing numbers 2025-05-28BUG/MINOR: limits: compute_ideal_maxconn: don't cap remain if fd_hard_limit=0 2025-05-28BUG/MINOR: h3: Set HTX flags corresponding to the scheme found in the request 2025-05-28BUG/MINOR: mux-h2: Reset streams with NO_ERROR code if full response was already sent 2025-05-28BUG/MINOR: sink: detect and warn when using "send-proxy" options with ring servers 2025-05-28BUG/MINOR: hlua: Fix Channel:data() and Channel:line() to respect documentation 2025-05-28BUG/MINOR: cli: fix too many args detection for commands 2025-05-28BUG/MINOR: quic: reject invalid max_udp_payload size 2025-05-28BUG/MINOR: quic: fix TP reject on invalid max-ack-delay 2025-05-28BUG/MINOR: quic: use proper error code on invalid received TP value 2025-05-28BUG/MINOR: quic: reject retry_source_cid TP on server side 2025-05-28BUG/MINOR: quic: use proper error code on invalid server TP 2025-05-28BUG/MINOR: quic: use proper error code on missing CID in TPs 2025-05-28BUG/MINOR: mux-h1: Fix trace message in h1_detroy() to not relay on connection 2025-05-28BUG/MINOR: mux-h1: Don't pretend connection was released for TCP>H1>H2 upgrade 2025-05-28BUG/MINOR: dns: add tempo between 2 connection attempts for dns servers 2025-05-28BUG/MINOR: cli: Issue an error when too many args are passed for a command 2025-04-22BUG/MINOR: mux-quic: fix BUG_ON() crash on init failure after app-ops 2025-04-22BUG/MINOR: mux-h2: prevent past scheduling with idle connections 2025-04-22BUG/MINOR: quic: do not crash on CRYPTO ncbuf alloc failure 2025-04-22BUG/MINOR: h3: reject request URI with invalid characters 2025-04-22BUG/MINOR: h3: reject invalid :path in request 2025-04-22BUG/MINOR: h3: filter upgrade connection header 2025-04-22BUG/MEDIUM: h3: trim whitespaces in header value prior to QPACK encoding 2025-04-22BUG/MEDIUM: h3: trim whitespaces when parsing headers value 2025-04-17BUG/MINOR: sink: add tempo between 2 connection attempts for sft servers (2) 2025-04-17BUG/MINOR: hlua: fix invalid errmsg use in hlua_init() 2025-04-17BUG/MINOR: backend: do not use the source port when hashing clientip 2025-04-17BUG/MEDIUM: sample: fix risk of overflow when replacing multiple regex back-refs 2025-04-17BUG/MEDIUM: backend: fix reuse with set-dst/set-dst-port 2025-04-17BUG/MINOR: backend: do not overwrite srv dst address on reuse 2025-04-17BUG/MINOR: log: fix gcc warn about truncating NUL terminator while init char arrays 2025-04-17BUG/MEDIUM: peers: prevent learning expiration too far in futur from unsync node 2025-04-17BUG/MINOR: peers: fix expire learned from a peer not converted from ms to ticks 2025-04-17BUG/MEDIUM: hlua/cli: fix cli applet UAF in hlua_applet_wakeup() 2025-04-17BUG/MINOR: namespace: handle a possible strdup() failure 2025-04-17BUG/MINOR: server: dont return immediately from parse_server() when skipping checks 2025-04-17BUG/MINOR: cfgparse/peers: properly handle ignored local peer case 2025-04-17BUG/MINOR: cfgparse/peers: fix inconsistent check for missing peer server 2025-04-17BUG/MEIDUM: startup: return to initial cwd only after check_config_validity() 2025-04-17BUG/MINOR: server: check for either proxy-protocol v1 or v2 to send hedaer 2025-04-17BUG/MINOR: h2: always trim leading and trailing LWS in header values 2025-04-17BUG/MINOR: sink: add tempo between 2 connection attempts for sft servers 2025-04-17BUG/MINOR: cfgparse: fix NULL ptr dereference in cfg_parse_peers 2025-04-17BUG/MINOR: stats-json: Define JSON_INT_MAX as a signed integer 2025-04-17BUG/MINOR: flt-trace: Support only one name option 2025-04-17BUG/MINOR: auth: Fix a leak on error path when parsing user's groups 2025-04-17BUG/MINOR: config/userlist: Support one 'users' option for 'group' directive 2025-04-17BUG/MINOR: cli: Fix a possible infinite loop in _getsocks() 2025-04-17BUG/MINOR: cli: Fix memory leak on error for _getsocks command 2025-04-17BUG/MINOR: tcp-rules: Don't forward close during tcp-response content rules eval 2025-04-17BUG/MINOR: quic: prevent crash on conn access after MUX init failure 2025-04-17BUG/MINOR: fcgi: Don't set the status to 302 if it is already set 2025-04-17BUG/MEDIUM: filters: Handle filters registered on data with no payload callback 2025-04-17BUG/MINOR: cli: Wait for the last ACK when FDs are xferred from the old worker 2025-04-17BUG/MINOR: quic: fix CRYPTO payload size calcul for encoding 2025-04-17BUG/MINOR: quic: reserve length field for long header encoding 2025-04-17BUG/MINOR: server: fix the "server-template" prefix memory leak 2025-04-16BUG/MEDIUM: thread: use pthread_self() not ha_pthread[tid] in set_affinity 2025-04-16BUG/MEDIUM: htx: wrong count computation in htx_xfer_blks() 2025-04-16BUG/MEDIUM: fd: mark FD transferred to another process as FD_CLONED 2025-04-16BUG/MEDIUM: clock: make sure now_ms cannot be TICK_ETERNITY 2025-02-19BUG/MEDIUM: spoe: Don't wakeup idle applets in loop during stopping 2025-02-19BUG/MINOR: spoe: Allow applet creation when closing the last one during stopping 2025-02-19BUG/MINOR: spoe: Check the shared waiting queue to shut applets during stopping 2025-02-19BUG/MINOR: http-ana: Disable fast-fwd for unfinished req waiting for upgrade 2025-02-19BUG/MEDIUM: mux-h1/mux-h2: Reject upgrades with payload on H2 side only 2025-02-19BUG/MINOR: h2: reject extended connect for h2c protocol 2025-02-19BUG/MINOR: h1: do not forward h2c upgrade header token 2025-02-19BUG/MINOR: ssl_sock: fix xprt_set_used() to properly clear the TASK_F_USR1 bit 2025-02-11BUG/MEDIUM: ssl: chosing correct certificate using RSA-PSS with TLSv1.3 2025-01-28BUG/MINOR: stream: Properly handle "on-marked-up shutdown-backup-sessions" 2025-01-28BUG/MINOR: ssl: put ssl_sock_load_ca under SSL_NO_GENERATE_CERTIFICATES 2025-01-28BUG/MINOR: quic: do not increase congestion window if app limited 2025-01-23MINOR: quic: Add a BUG_ON() on quic_tx_packet refcount 2025-01-23BUG/MINOR: quic: ensure a detached coalesced packet can't access its neighbours 2025-01-23BUG/MAJOR: quic: reject too large CRYPTO frames 2025-01-23BUG/MEDIUM: stktable: fix missing lock on some table converters 2025-01-23BUG/MINOR: quic: reject NEW_TOKEN frames from clients 2025-01-23BUG/MINOR: stktable: fix big-endian compatiblity in smp_to_stkey() 2025-01-09BUG/MEDIUM: queue: Make process_srv_queue return the number of streams 2025-01-09BUG/MEDIUM: queues: Do not use pendconn_grab_from_px(). 2025-01-09BUG/MEDIUM: queues: Make sure we call process_srv_queue() when leaving 2025-01-09BUG/MEDIUM: stconn: Don't forward shut for SC in connecting state 2025-01-09BUG/MINOR: stream: unblock stream on wait-for-handshake completion 2025-01-09BUG/MEDIUM: pattern: prevent uninitialized reads in pat_match_{str,beg} 2025-01-09BUG/MEDIUM: mux-h1: Fix how timeouts are applied on H1 connections 2025-01-09BUG/MINOR: server-state: Fix expiration date of srvrq_check tasks 2025-01-09BUG/MINOR: signal: register default handler for SIGINT in signal_init() 2025-01-09BUG/MINOR: h1-htx: Use default reason if not set when formatting the response 2025-01-09BUG/MEDIUM: http-ana: Reset request flag about data sent to perform a L7 retry 2025-01-09BUG/MEDIUM: sock: Remove FD_POLL_HUP during connect() if FD_POLL_ERR is not set 2025-01-09BUG/MEDIUM: http-ana: Don't release too early the L7 buffer 2025-01-09BUG/MAJOR: quic: fix wrong packet building due to already acked frames 2025-01-09BUG/MEDIUM: h3: Increase max number of headers when sending headers 2025-01-09BUG/MEDIUM: h3: Properly limit the number of headers received 2025-01-09BUG/MEDIUM: mux-h2: Check the number of headers in HEADERS frame after decoding 2025-01-09BUG/MEDIUM: mux-h2: Increase max number of headers when encoding HEADERS frames 2025-01-09BUG/MINOR: http-ana: Adjust the server status before the L7 retries 2025-01-09BUG/MINOR: http_ana: Report -1 for %Tr for invalid response only 2025-01-09BUG/MINOR: peers: make sure to always apply offsets to now_ms in expiration 2025-01-09BUG/MEDIUM: mailers: make sure to always apply offsets to now_ms in expiration 2025-01-09BUG/MEDIUM: checks: make sure to always apply offsets to now_ms in expiration 2025-01-09BUG/MEDIUM: mux-h2: Don't send RST_STREAM frame for streams with no ID 2025-01-09BUG/MEDIUM: resolvers: Insert a non-executed resulution in front of the wait list 2025-01-09BUG/MINOR: cli: don't show sockpairs in HAPROXY_CLI and HAPROXY_MASTER_CLI 2025-01-09BUG/MEDIUM: queue: make sure never to queue when there's no more served conns 2025-01-09BUG/MEDIUM: queue: always dequeue the backend when redistributing the last server 2025-01-09BUG/MEDIUM: stream: make stream_shutdown() async-safe 2024-11-08BUG/MEDIUM: mux-pt: Never fully close the connection on shutdown 2024-11-06BUG/MINOR: http-ana: Report internal error if an action yields on a final eval 2024-11-06BUG/MINOR: ssl/cli: 'set ssl cert' does not check the transaction name correctly 2024-11-06BUG/MEDIUM: server: fix race on servers_list during server deletion 2024-11-06BUG/MINOR: server: fix dynamic server leak with check on failed init 2024-11-06BUG/MEDIUM: connection/http-reuse: fix address collision on unhandled address families 2024-11-06BUG/MINOR: mworker: fix mworker-max-reloads parser 2024-11-06BUG/MINOR: http-ana: Don't report a server abort if response payload is invalid 2024-11-06BUG/MEDIUM: hlua: properly handle sample func errors in hlua_run_sample_{fetch,conv}() 2024-11-06BUG/MEDIUM: hlua: make hlua_ctx_renew() safe 2024-11-06BUG/MEDIUM: server: server stuck in maintenance after FQDN change 2024-11-06BUG/MINOR: cfgparse-global: fix allowed args number for setenv 2024-11-06BUG/MEDIUM: cli: Deadlock when setting frontend maxconn 2024-09-18BUG/MINOR: cfgparse-listen: fix option httpslog override warning message 2024-09-17BUG/MEDIUM: promex: Wait to have the request before sending the response 2024-09-17BUG/MEDIUM: cache/stats: Wait to have the request before sending the response 2024-09-17BUG/MEDIUM: queue: implement a flag to check for the dequeuing 2024-09-17BUG/MINOR: polling: fix time reporting when using busy polling 2024-09-17BUG/MEDIUM: pattern: prevent UAF on reused pattern expr 2024-09-17BUG/MINOR: pattern: prevent const sample from being tampered in pat_match_beg() 2024-09-17BUG/MINOR: pattern: do not leave a leading comma on "set" error messages 2024-09-17BUG/MINOR: pattern: pat_ref_set: return 0 if err was found 2024-09-17BUG/MINOR: pattern: pat_ref_set: fix UAF reported by coverity 2024-09-17BUG/MINOR: h3: properly reject too long header responses 2024-09-17BUG/MINOR: proto_uxst: delete fd from fdtab if listen() fails 2024-09-17BUG/MINOR: mux-quic: do not send too big MAX_STREAMS ID 2024-09-17BUG/MINOR: proto_tcp: keep error msg if listen() fails 2024-09-17BUG/MINOR: proto_tcp: delete fd from fdtab if listen() fails 2024-09-17BUG/MINOR: quic/trace: make quic_conn_enc_level_init() emit NEW not CLOSE 2024-09-17BUG/MINOR: trace/quic: make "qconn" selectable as a lockon criterion 2024-09-17BUG/MINOR: trace: automatically start in waiting mode with "start " 2024-09-17BUG/MINOR: trace/quic: permit to lock on frontend/connect/session etc 2024-09-17BUG/MINOR: trace/quic: enable conn/session pointer recovery from quic_conn 2024-09-17BUG/MINOR: fcgi-app: handle a possible strdup() failure 2024-09-17BUG/MEDIUM: h2: Only report early HTX EOM for tunneled streams 2024-09-17BUG/MEDIUM: quic: prevent conn freeze on 0RTT undeciphered content 2024-09-17BUG/MEDIUM: cli: Always release back endpoint between two commands on the mcli 2024-09-17BUG/MEDIUM: stream: Prevent mux upgrades if client connection is no longer ready 2024-07-31BUG/MEDIUM: init: fix fd_hard_limit default in compute_ideal_maxconn 2024-07-31BUG/MEDIUM: queue: deal with a rare TOCTOU in assign_server_and_queue() 2024-07-31BUG/MINOR: cli: Atomically inc the global request counter between CLI commands 2024-07-31BUG/MINOR: server: Don't warn fallback IP is used during init-addr resolution 2024-07-31BUG/MINOR: stick-table: fix crash for src_inc_gpc() without stkcounter 2024-07-31BUG/MEDIUM: spoe: Be sure to create a SPOE applet if none on the current thread 2024-07-31BUG/MEDIUM: h1: Reject empty Transfer-encoding header 2024-07-31BUG/MINOR: h1: Reject empty coding name as last transfer-encoding value 2024-07-31BUG/MINOR: h1: Fail to parse empty transfer coding names 2024-07-31BUG/MEDIUM: jwt: Clear SSL error queue on error when checking the signature 2024-07-31BUG/MINOR: jwt: fix variable initialisation 2024-07-31BUG/MINOR: jwt: don't try to load files with HMAC algorithm 2024-07-31BUG/MINOR: quic: Lack of precision when computing K (cubic only cc) 2024-07-03BUG/MEDIUM: h3: ensure the ":scheme" pseudo header is totally valid 2024-07-03BUG/MEDIUM: h3: ensure the ":method" pseudo header is totally valid 2024-07-03BUG/MINOR: hlua: report proper context upon error in hlua_cli_io_handler_fct() 2024-07-03BUG/MINOR: quic: fix BUG_ON() on Tx pkt alloc failure 2024-07-03BUG/MINOR: mux-quic: fix crash on qcs SD alloc failure 2024-07-03BUG/MINOR: quic: fix computed length of emitted STREAM frames 2024-06-19BUG/MEDIUM: cli: fix cli_output_msg() regression 2024-06-07BUG/MINOR: haproxy: only tid 0 must not sleep if got signal 2024-06-07BUG/MEDIUM: quic: don't blindly rely on unaligned accesses 2024-06-07BUG/MAJOR: connection: fix server used_conns with H2 + reuse safe 2024-06-07BUG/MEDIUM: http_ana: ignore NTLM for reuse aggressive/always and no H1 2024-06-07BUG/MAJOR: server: do not delete srv referenced by session 2024-06-07BUG/MEDIUM: quic: fix connection freeze on post handshake 2024-06-07BUG/MEDIUM: server: fix dynamic servers initial settings 2024-06-07BUG/MEDIUM: ssl: wrong priority whem limiting ECDSA ciphers in ECDSA+RSA configuration 2024-06-07BUG/MINOR: hlua: fix leak in hlua_ckch_set() error path 2024-06-07BUG/MINOR: hlua: prevent LJMP in hlua_traceback() 2024-06-07BUG/MINOR: hlua: fix unsafe hlua_pusherror() usage 2024-06-07BUG/MINOR: hlua: don't use lua_pushfstring() when we don't expect LJMP 2024-06-07BUG/MINOR: quic: prevent crash on qc_kill_conn() 2024-06-07BUG/MINOR: hlua: use CertCache.set() from various hlua contexts 2024-06-07BUG/MINOR: tools: fix possible null-deref in env_expand() on out-of-memory 2024-06-07BUG/MINOR: tcpcheck: report correct error in tcp-check rule parser 2024-06-07BUG/MINOR: cfgparse: remove the correct option on httpcheck send-state warning 2024-06-07BUG/MINOR: activity: fix Delta_calls and Delta_bytes count 2024-06-07BUG/MINOR: ssl/ocsp: init callback func ptr as NULL 2024-06-07BUG/MINOR: server: Don't reset resolver options on a new default-server line 2024-06-07BUG/MINOR: http-htx: Support default path during scheme based normalization 2024-06-07BUG/MINOR: quic: adjust restriction for stateless reset emission 2024-06-07BUG/MEDIUM: mux-quic: Create sedesc in same time of the QUIC stream 2024-06-07BUG/MEDIUM: quic_tls: prevent LibreSSL < 4.0 from negotiating CHACHA20_POLY1305 2024-06-07BUG/MAJOR: quic: Crash with TLS_AES_128_CCM_SHA256 (libressl only) 2024-06-07BUG/MINOR: connection: parse PROXY TLV for LOCAL mode 2024-06-07BUG/MINOR: stats: Don't state the 303 redirect response is chunked 2024-06-07BUG/MINOR: htpp-ana/stats: Specify that HTX redirect messages have a C-L header 2024-06-07BUG/MEDIUM: fd: prevent memory waste in fdtab array 2024-06-07BUG/MEDIUM: h1: Reject CONNECT request if the target has a scheme 2024-06-07BUG/MINOR: h1: Check authority for non-CONNECT methods only if a scheme is found 2024-06-07BUG/MEDIUM: stick-tables: properly mark stktable_data as packed 2024-06-07BUG/MEDIUM: htx: mark htx_sl as packed since it may be realigned 2024-06-07BUG/MINOR: qpack: fix error code reported on QPACK decoding failure 2024-06-07BUG/MINOR: mux-quic: fix error code on shutdown for non HTTP/3 2024-06-07BUG/MINOR: log: smp_rgs array issues with inherited global log directives 2024-06-07BUG/MINOR: log: keep the ref in dup_logger() 2024-06-07BUG/MINOR: mworker: reintroduce way to disable seamless reload with -x /dev/null 2024-06-07BUG/MINOR: h1: fix detection of upper bytes in the URI 2024-06-07BUG/MINOR: backend: use cum_sess counters instead of cum_conn 2024-06-07BUG/MINOR: fd: my_closefrom() on Linux could skip contiguous series of sockets 2024-06-07BUG/MINOR: sock: handle a weird condition with connect() 2024-06-07BUG/MINOR: stconn: Fix sc_mux_strm() return value 2024-06-07BUG/MEDIUM: cache: Vary not working properly on anything other than accept-encoding 2024-04-19BUG/MINOR: server: fix slowstart behavior 2024-04-19BUG/MEDIUM: peers: Fix exit condition when max-updates-at-once is reached 2024-04-19BUG/MEDIUM: evports: do not clear returned events list on signal 2024-04-19BUG/MEDIUM: stconn: Don't forward channel data if input data must be filtered 2024-04-19BUG/MEDIUM: grpc: Fix several unaligned 32/64 bits accesses 2024-04-19BUG/MEDIUM: peers/trace: fix crash when listing event types 2024-04-19BUG/MINOR: debug: make sure DEBUG_STRICT=0 does work as documented 2024-04-19BUG/MINOR: http-ana: Fix TX_L7_RETRY and TX_D_L7_RETRY values 2024-04-19BUG/MEDIUM: http-ana: Deliver 502 on keep-alive for fressh server connection 2024-04-19BUG/MINOR: log: invalid snprintf() usage in sess_build_logline() 2024-04-19BUG/MINOR: tools/log: invalid encode_{chunk,string} usage 2024-04-19BUG/MINOR: log: fix lf_text_len() truncate inconsistency 2024-04-08BUG/MEDIUM: cli: Warn if pipelined commands are delimited by a \n 2024-04-08BUG/MINOR: ext-check: cannot use without preserve-env 2024-04-08BUG/MEDIUM: quic: remove unsent data from qc_stream_desc buf 2024-04-08BUG/MEDIUM: mux-quic: report early error on stream 2024-04-08BUG/MEDIUM: cli: fix once for all the problem of missing trailing LFs 2024-04-05BUG/MINOR: proxy: fix logformat expression leak in use_backend rules 2024-04-05BUG/MEDIUM: hlua: streams don't support mixing lua-load with lua-load-per-thread (2nd try) 2024-04-05DEBUG: lua: precisely identify if stream is stuck inside lua or not 2024-04-03BUG/MINOR: backend: properly handle redispatch 0 2024-04-03BUG/MINOR: server: ignore 'enabled' for dynamic servers 2024-04-03BUG/MINOR: server: 'source' interface ignored from 'default-server' directive 2024-04-03BUG/MEDIUM: mux-fcgi: Properly handle EOM flag on end-of-trailers HTX block 2024-04-03BUG/MINOR: mux-quic: close all QCS before freeing QCC tasklet 2024-04-03BUG/MINOR: session: ensure conn owner is set after insert into session 2024-04-03BUG/MEDIUM: spoe: Return an invalid frame on recv if size is too small 2024-04-03BUG/MINOR: spoe: Be sure to be able to quickly close IDLE applets on soft-stop 2024-04-03BUG/MEDIUM: spoe: Don't rely on stream's expiration to detect processing timeout 2024-04-03BUG/MINOR: listener: Don't schedule frontend without task in listener_release() 2024-04-03BUG/MINOR: listener: Wake proxy's mngmt task up if necessary on session release 2024-04-03BUG/MINOR: hlua: fix missing lock in hlua_filter_delete() 2024-04-03BUG/MINOR: hlua: missing lock in hlua_filter_new() 2024-04-03BUG/MINOR: hlua: segfault when loading the same filter from different contexts 2024-04-03BUG/MINOR: ssl: fix possible ctx memory leak in sample_conv_aes_gcm() 2024-04-03BUG/MINOR: cfgparse: report proper location for log-format-sd errors 2024-04-03BUG/MINOR: ssl/cli: typo in new ssl crl-file CLI description 2024-04-03BUG/MAJOR: hlua: improper lock usage with hlua_ctx_resume() 2024-04-03BUG/MEDIUM: hlua: improper lock usage with SET_SAFE_LJMP() 2024-04-03BUG/MINOR: hlua: improper lock usage in hlua_filter_new() 2024-04-03BUG/MINOR: hlua: improper lock usage in hlua_filter_callback() 2024-04-03BUG/MINOR: hlua: fix possible crash in hlua_filter_new() under load 2024-04-03BUG/MINOR: hlua: don't use lua_tostring() from unprotected contexts 2024-04-03BUG/MINOR: hlua: fix unsafe lua_tostring() usage with empty stack 2024-04-03BUG/MINOR: tools: seed the statistical PRNG slightly better 2024-04-03BUG/MINOR: hlua: Fix log level to the right value when set via TXN:set_loglevel 2024-04-03BUG/MINOR: ssl/cli: duplicate cleaning code in cli_parse_del_crtlist 2024-04-03BUG/MINOR: ist: only store NUL byte on succeeded alloc 2024-04-03BUG/MAJOR: server: fix stream crash due to deleted server 2024-04-03BUG/MINOR: stats: drop srv refcount on early release 2024-04-03BUG/MINOR: ist: allocate nul byte on istdup 2024-04-03BUG/MEDIUM: hlua: Don't loop if a lua socket does not consume received data 2024-04-03BUG/MEDIUM: hlua: Be able to garbage collect uninitialized lua sockets 2024-04-03BUG/MEDIUM: applet: Immediately free appctx on early error 2024-04-03BUG/MINOR: qpack: reject invalid dynamic table capacity 2024-04-03BUG/MINOR: qpack: reject invalid increment count decoding 2024-04-03BUG/MINOR: quic: reject HANDSHAKE_DONE as server 2024-04-03BUG/MINOR: quic: reject unknown frame type 2024-04-03BUG/MAJOR: promex: fix crash on deleted server 2024-04-03BUG/MINOR: diag: run the final diags before quitting when using -c 2024-04-03BUG/MEDIUM: quic: Wrong K CUBIC calculation. 2024-04-03BUG/MINOR: quic: fix possible integer wrap around in cubic window calculation 2024-04-03BUG/MINOR: quic: Wrong ack ranges handling when reaching the limit. 2024-04-03BUG/MEDIUM: quic: fix crash on invalid qc_stream_buf_free() BUG_ON 2024-04-03BUG/MEDIUM: qpack: allow 6xx..9xx status codes 2024-04-03BUG/MEDIUM: h3: do not crash on invalid response status code 2024-04-03BUG/MINOR: h3: fix checking on NULL Tx buffer 2024-04-03BUG/MINOR: ssl: Clear the ckch instance when deleting a crt-list line 2024-04-03BUG/MAJOR: ssl_sock: Always clear retry flags in read/write functions 2024-04-03BUG/MEDIUM: h1: always reject the NUL character in header values 2024-04-03BUG/MEDIUM: h1: Don't support LF only to mark the end of a chunk size 2024-04-03BUG/MINOR: h1: Don't support LF only at the end of chunks 2024-04-03BUG/MINOR: h1-htx: properly initialize the err_pos field 2024-04-03BUG/MEDIUM: pool: fix rare risk of deadlock in pool_flush() 2024-04-03BUG/MINOR: jwt: fix jwt_verify crash on 32-bit archs 2024-04-03BUG/MINOR: vars/cli: fix missing LF after "get var" output 2024-04-03BUG/MEDIUM: cli: some err/warn msg dumps add LR into CSV output on stat's CLI 2024-04-03MINOR: debug: make BUG_ON() catch build errors even without DEBUG_STRICT 2024-01-19BUG/MINOR: mux-quic: do not prevent non-STREAM sending on flow control 2024-01-19BUG/MEDIUM: h3: fix regression which completely prevents any send 2024-01-17BUG/MEDIUM: spoe: Never create new spoe applet if there is no server up 2024-01-17BUG/MEDIUM: stconn: Forward shutdown on write timeout only if it is forwardable 2024-01-17BUG/MEDIUM: h3: fix incorrect snd_buf return value 2024-01-17BUG/MINOR: h3: close connection on sending alloc errors 2024-01-17BUG/MINOR: h3: properly handle alloc failure on finalize 2024-01-17BUG/MINOR: h3: close connection on header list too big 2024-01-17BUG/MEDIUM: stats: unhandled switching rules with TCP frontend 2024-01-17BUG/MINOR: resolvers: default resolvers fails when network not configured 2024-01-17BUG/MEDIUM: mux-h2: Report too large HEADERS frame only when rxbuf is empty 2024-01-17BUG/MINOR: mworker/cli: fix set severity-output support 2024-01-17BUG/MEDIUM: proxy: always initialize the default settings after init 2024-01-17BUG/MEDIUM: mworker: set the master variable earlier 2024-01-17BUG/MEDIUM: connection: report connection errors even when no mux is installed