PatchSiren

HAProxy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH haproxy CVE published 2026-06-18

CVE-2026-55204

CVE-2026-55204 is a high-severity vulnerability in HAProxy, a popular open-source load balancer. The vulnerability, caused by a null pointer dereference in the hpack_dht_insert() function, allows an attacker to crash HAProxy worker processes, leading to a denial of service (DoS). This vulnerability affects HAProxy versions up to 3.4.0 and was fixed in commit 9a6d1fe. An attacker can exploit this vulnerabi [truncated]

CRITICAL haproxy CVE published 2026-06-18

CVE-2026-55203

A critical vulnerability, CVE-2026-55203, has been discovered in HAProxy, a popular open-source load balancer and proxy server. This integer overflow vulnerability affects HAProxy versions up to 3.4.0 and allows malicious FastCGI backends to desynchronize the FCGI framing parser. Successful exploitation could lead to request routing errors, response smuggling, or memory safety issues. The vulnerability ha [truncated]

MEDIUM HAProxy CVE published 2026-04-13

CVE-2026-33555

CVE-2026-33555 is a vulnerability in HAProxy's HTTP/3 parser. The parser does not check if the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This oversight can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version of HAProxy is 2.6.0. This issue was addr [truncated]