HAProxy known bugs for version v2.8.25 (maintenance branch 2.8) :  86 

This version (2.8.25) is a release belonging to maintenance branch 2.8 whose latest version is 2.8.28. If your version is not the last one in the maintenance branch, you are missing fixes for known bugs, and by not updating you are needlessly taking the responsibility for the risk of unexpected service outages and exposing your web site to possible security issues.

The HAProxy development team takes a great care of maintaining stable versions so that all users can apply bug fixes without having to take the risk of upgrading to a new branch. In turn users are expected to apply the fixes when the development team estimates that they were worth being backported to stable branches.

Quick links

Other versions in the same branch

This branch contains the following releases :

DateVersionComment
2026-08-272.8.28 ⇐ last
2026-07-292.8.27 
2026-07-032.8.26 
2026-06-262.8.25 ⇐ yours
2026-05-112.8.24 
2026-05-062.8.23 
2026-04-302.8.22 
2026-04-232.8.21 
2026-03-202.8.20 
2026-03-092.8.19 
2025-12-252.8.18 
2025-12-192.8.17 
2025-10-032.8.16 
2025-04-222.8.15 
2025-01-292.8.14 
2024-12-122.8.13 
2024-11-082.8.12 
2024-09-192.8.11 
2024-06-142.8.10 
2024-04-052.8.9 
2024-04-052.8.8 
2024-02-262.8.7 
2024-02-152.8.6 
2023-12-072.8.5 
2023-11-172.8.4 
2023-09-072.8.3 
2023-08-092.8.2 
2023-07-032.8.1 
2023-05-312.8.0 

Known bugs affecting this version, and already fixed in the maintenance branch

These fixes have already been queued for a more recent 2.8 version. Some of them might have already been released in a more recent version than yours, and other ones might still be pending in the maintenance branch for a future release. The list may be empty if you're already on the latest version and no new fix was backported.

Bugs are almost always tagged with a severity (some people forget the severity tag when the bug is minor). The following severities are used :

Total known bugs in this version by category :

TotalCRITICALMAJORMEDIUMMINOR
86 0 2 28 56

Click on the subjects below to get the full description of the bug :

Merge dateSubject - Severity (minor, medium, major, critical)
2026-08-26BUG/MINOR: flt-http-comp: Don't read next block to detect end of data
2026-08-26BUG/MINOR: fcgi-app: allow explicit filter declaration with non-cache/non-compression filters
2026-08-26BUG/MEDIUM: cache: ignore cache on redundant origin/referer
2026-08-26BUG/MINOR: mux-h2: harden h2_dump_h2s_info() against potentially null h2s->sd
2026-08-26BUG/MINOR: cfgcond: make KQUEUE check for GTUNE_USE_KQUEUE not GTUNE_USE_EPOLL
2026-08-26BUG/MINOR: auth: free user groups on error paths in userlist_postinit()
2026-08-26BUG/MINOR: tools: fix memory leak in env_expand() error path
2026-08-26BUG/MINOR: http-act: set-status() must check the response message, not the request
2026-08-26BUG/MINOR: http-fetch: make http_first_req() check for HTTP first
2026-08-26BUG/MINOR: http-fetch: fix smp_fetch_hdr_ip()'s handling of brackets for IPv6
2026-08-26BUG/MINOR: ot: removed dead code in flt_ot_parse_cfg_str()
2026-08-26BUG/MINOR: config: Check buffer pool creation for failures
2026-08-26BUG/MINOR: wurfl: fix memory leak of information list and patch strings at deinit
2026-08-26BUG/MEDIUM: mux-fcgi: check the room left before appending the index
2026-08-26BUG/MINOR: resolvers: accept fields at the response boundary
2026-08-26BUG/MEDIUM: ssl: isolate TLS session resumption per authentication policy
2026-08-26BUG/MINOR: ssl: isolate TLS session resumption per crt-list filter
2026-08-26BUG/MEDIUM: ssl: isolate TLS session resumption per X509 server certificate
2026-08-26BUG/MINOR: ssl: apply tune.ssl.lifetime to TLS1.3 sessions on BoringSSL/AWS-LC
2026-08-26BUG/MEDIUM: ssl: enforce tune.ssl.lifetime across TLS1.3 session renewals
2026-08-26BUG/MINOR: ssl: release the previous client cert reference at depth > 0
2026-08-26BUG/MINOR: conn: Do not check 'sess_el' list on frontend connections in __trace_enabled
2026-08-26BUG/MINOR: qpack: missing shift count check in qpack_get_varint() (UB)
2026-08-26BUG/MINOR: spoe: check snprintf() return value in spoe_set_var/spoe_unset_var
2026-08-26BUG/MINOR: payload: fix handshake length off-by-4 in ssl_hello_sni/alpn
2026-08-26BUG/MEDIUM: bwlim: fix a stick-table entry leak in shared mode
2026-08-26BUG/MEDIUM: http: fix authority parsing for absolute-form URI with empty path
2026-08-26BUG/MEDIUM: lua: resume Channel:send() from the unsent part of the string
2026-08-26BUG/MEDIUM: quic: prevent out-of-bound read on wrapping CRYPTO content
2026-08-26BUG/MINOR: mux-h2: strip the userinfo when deriving :authority for a server
2026-08-26BUG/MINOR: lb-chash: bound the walk when the saved cursor changed tree
2026-08-26BUG/MINOR: connection: reserve the whole CRC32C TLV before saving its pointer
2026-08-26BUG/MINOR: ssl: reject server certificate names containing a NUL byte
2026-08-26BUG/MINOR: mux-fcgi: sanitize the STDERR records before logging them
2026-08-26BUG/MEDIUM: http-ana: check the cookie rewrite result before moving the offsets
2026-08-26BUG/MEDIUM: sock: bound the recvmsg() length when receiving old sockets
2026-08-26BUG/MINOR: mux-fcgi: don't call fcgi_strm_destroy() on a NULL stream
2026-08-26BUG/MINOR: hlua: use a local buffer to format the socket addresses
2026-08-26BUG/MEDIUM: hpack: encode long methods and schemes using the long form
2026-08-26BUG/MINOR: proxy: fix default-server leak on post-parsing cleanup
2026-08-26BUG/MINOR: server: check strdup return value on server ID
2026-08-26BUG/MEDIUM: filter: Disable auto-close on channel during TCP payload filtering
2026-08-26BUG/MINOR: cli: use the current argument to parse the FD spec in "show fd"
2026-07-29BUG/MAJOR: ssl/ocsp: lock the OCSP response around reads in the stapling callback
2026-07-29BUG/MEDIUM: sample: reject the deprecated protobuf group wire types
2026-07-29BUG/MEDIUM: peers: check the available room before encoding dict values
2026-07-29BUG/MINOR: slz: avoid undefined shifts when building the word byte by byte
2026-07-29BUG/MINOR: slz: fix the adler32 accumulators signedness on 32-bit
2026-07-29BUG/MINOR: slz: do not append a block to an already finished stream
2026-07-29BUG/MEDIUM: slz: bound the bits wasted by the 9-bit literals
2026-07-29BUG/MINOR: slz: use the exact switch cost for the last literals of a block
2026-07-29BUG/MINOR: slz: do not read past the end of the input around the match loop
2026-07-29BUG/MINOR: htx: Transfer HTX_FL_EOM flag on success in htx_append_msg()
2026-07-29BUG/MINOR: htx: Perform raw copy for messages of same size in htx_copy_msg()
2026-07-29BUG/MINOR: http-htx: check the strdup() of the "lf-string" http reply argument
2026-07-29BUG/MINOR: http-act: reject a negative capture id in the capture actions
2026-07-29BUG/MINOR: http-act: restore the response buffer state in the early-hint action
2026-07-29BUG/MINOR: http-act: fix a double free of the map reference on a parsing error
2026-07-29BUG/MINOR: http-act: fix a double free of the regex on a rule parsing error
2026-07-29BUG/MINOR: http-ana: fix a one-byte over-read in the client-side cookie parser
2026-07-29BUG/MINOR: h2: don't use a block pointer to roll back a partial HTX conversion
2026-07-29BUG/MINOR: http-htx: check the trash allocation in http_scheme_based_normalize()
2026-07-29BUG/MINOR: http: fix an out-of-bounds read in http_get_host_port() on empty host
2026-07-29BUG/MEDIUM: http-fetch: reject a negative capture id in capture.{req,res}.hdr
2026-07-29BUG/MEDIUM: http-fetch: don't parse a non-HTTP check buffer as an HTX message
2026-07-29BUG/MINOR: http-htx: fix the length moved when removing a header value
2026-07-23BUG/MEDIUM: applet: Reenable reads in applet context if requesting a connection
2026-07-22BUG/MEDIUM: sample: Adjust sample size capacity after pointer shift for ltrim()
2026-07-22BUG/MINOR: mux-h1: Don't delay send if message with c-l was fully sent
2026-07-22BUG/MEDIUM: protobuf: fix nested path bypass in field lookup
2026-07-22BUG/MEDIUM: protobuf: adjust sample size capacity after pointer shift
2026-07-22BUG/MEDIUM: ssl-gencert: Don't forget to free memory when done
2026-07-22BUG/MEDIUM: stats: Ensure that Origin is valid on POSTs
2026-07-22BUG/MEDIUM: stats: subject "stats admin" accesses to "stats scope" filtering
2026-07-22BUG/MINOR: hlua: Apply socket timeout on server side only
2026-07-22BUG/MINOR: http-conv: Make url-dec failed if no space for trailing null byte
2026-07-22BUG/MINOR: stream: Fix custom timeouts initialization when setting backend
2026-07-22BUG/MINOR: sample: Fix a possible underflow on be2hex for large chunk size
2026-07-22BUG/MEDIUM: fd: Fix a deadlock when closing other tgroups fds
2026-07-22BUG/MINOR: mux_quic: prevent multiple STOP_SENDING emission per stream
2026-07-22BUG/MEDIUM: h3: fix parser desync on error with multiple frames
2026-07-02BUG/MINOR: http-htx: Don't by-pass HTX API when merging cookie values
2026-07-02BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error
2026-07-02BUG/MINOR: tools: fix invalid character detection in strl2ic()
2026-07-02BUG/MINOR: sample: set SMP_F_CONST on srv_name fetch
2026-07-02BUG/MEDIUM: mux_quic: fix memory leak of rx app_buf on stream free

Back to the list of branches and versions
Back to the HAProxy page