PT-2026-50708 · Haproxy+2 · Haproxy+2

·

CVE-2026-55204

·

Published

2026-06-18

·

Updated

2026-07-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HAProxy versions prior to 3.4.0
Description A null pointer dereference occurs in the hpack dht insert() function within src/hpack-tbl.c because the return value of hpack dht defrag() is not validated when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to cause worker processes to crash, resulting in a denial of service.
Recommendations Update to the version containing commit 9a6d1fe.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-HAPROXY-2026-55204
CVE-2026-55204
OPENSUSE-SU-2026:11090-1
OPENSUSE-SU-2026:21245-1
SUSE-SU-2026:22515-1
SUSE-SU-2026:22544-1
SUSE-SU-2026:22557-1
SUSE-SU-2026:22587-1
SUSE-SU-2026:22663-1
SUSE-SU-2026:2651-1
SUSE-SU-2026:2652-1
USN-8459-1

Affected Products

Haproxy
Linuxmint
Ubuntu