PatchSiren

haproxy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH haproxy CVE published 2026-06-18

CVE-2026-55204

CVE-2026-55204 is a high-severity vulnerability in HAProxy, a popular open-source load balancer. The vulnerability, caused by a null pointer dereference in the hpack_dht_insert() function, allows an attacker to crash HAProxy worker processes, leading to a denial of service (DoS). This vulnerability affects HAProxy versions up to 3.4.0 and was fixed in commit 9a6d1fe. An attacker can exploit this vulnerabi [truncated]

CRITICAL haproxy CVE published 2026-06-18

CVE-2026-55203

A critical vulnerability, CVE-2026-55203, has been discovered in HAProxy, a popular open-source load balancer and proxy server. This integer overflow vulnerability affects HAProxy versions up to 3.4.0 and allows malicious FastCGI backends to desynchronize the FCGI framing parser. Successful exploitation could lead to request routing errors, response smuggling, or memory safety issues. The vulnerability ha [truncated]