← Vulnerability feed

Vulnerability record · CVE-2026-55203 · published 18 June 2026

CVE-2026-55203: Haproxy integer overflow vulnerability

Haproxy · Haproxy

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

9.0 CVSS 4.0 Critical EPSS 0.58% · top 54.7% CWE-190 · Integer overflow
9.0CVSS 4.0 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
14 Jul 2026Last modified by NVD

Description

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-55203 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19330Haproxy injection vulnerabilityThe HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa),…EPSS 4.0%9.1CVE-2023-25725Haproxy http request smuggling vulnerabilityHAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." …EPSS 5.4%8.8CVE-2020-11100HAProxy HPACK decoder heap out-of-bounds writeThe HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4 contains an out-of-bounds write in hpack_dht_insert in hpack-tbl.c. A crafted HTTP/2 reques…EPSS 61%analysed8.7CVE-2026-55204Haproxy null pointer dereference vulnerabilityHAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that f…EPSS 0.48%8.2CVE-2023-45539Haproxy vulnerabilityHAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified o…EPSS 1.5%7.5CVE-2025-11230Haproxy aloha appliance vulnerabilityInefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.EPSS 0.69%7.5CVE-2024-45506Haproxy vulnerabilityHAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_sen…EPSS 1.2%7.5CVE-2023-0836Haproxy information exposure vulnerabilityAn information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2026-55203), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.