Haproxy · Haproxy · CVE-2019-14241
**Name of the Vulnerable Software and Affected Versions**
HAProxy versions prior to 2.0.3
HAProxy through 2.0.2
**Description**
The issue is related to a denial of service condition that can be triggered by exploiting a loop with an unavailable exit condition. This can allow a remote attacker to cause a service disruption. The problem is associated with the `htx manage client side cookies` function in `proto htx.c`.
**Recommendations**
For HAProxy versions through 2.0.2, consider updating to a version later than 2.0.2 to resolve the issue.
As a temporary workaround, consider restricting access to the `proto htx.c` module to minimize the risk of exploitation.