CVE-2018-14645
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
Date published : 2018-09-21
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14645
https://www.mail-archive.com/haproxy@formilux.org/msg31253.html