logo

HAProxy Vulnerabilities Expose Reverse-Proxy Servers

ID: 364a62ca-b267-5d4e-8a46-586f4a1726f3

STIX ID: report--364a62ca-b267-5d4e-8a46-586f4a1726f3

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Do Son

...
...

Two critical HAProxy vulnerabilities affect releases up through 3.4.0: CVE-2026-55203 is an integer overflow in the FastCGI demux record length that can enable HTTP response smuggling, and CVE-2026-55204 is a NULL pointer dereference in hpack_dht_insert that can crash workers (DoS). Patches (commits 5985276 and 9a6d1fe) are available and administrators are urged to update immediately; no exploitation in the wild has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.