Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisory

HAProxy flaws enable FastCGI response smuggling and worker process crashes

Updated 1d agoFirst seen Jun 18, 20263 sources

Two newly disclosed vulnerabilities affect HAProxy through version 3.4.0, including CVE-2026-55203, a critical integer overflow in FastCGI handling that can be triggered by a malicious FastCGI backend. The bug resides in the fcgi_conn structure’s drl field: when contentLength is 65535 and paddingLength is 1 or greater, the value wraps to 0, causing the parser to treat buffered data as new FastCGI record headers. That desynchronization can lead to request routing errors, response smuggling, and possible memory-safety impacts. The issue is described as remotely exploitable and was fixed in commit 5985276.

A second flaw, CVE-2026-55204, is a high-severity NULL pointer dereference in hpack_dht_insert() within src/hpack-tbl.c. The vulnerability occurs when HAProxy fails to validate the return value of hpack_dht_defrag() after memory-pool exhaustion, allowing a remote attacker to trigger HPACK dynamic table insertions under memory pressure and crash HAProxy worker processes, resulting in denial of service. The bug is fixed in commit 9a6d1fe, and affected organizations should update HAProxy to a release containing both fixes.

Share:
HAProxy flaws enable FastCGI response smuggling and worker process crashes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 18, 20262d ago

CVE-2026-55204 published for HAProxy HPACK NULL dereference

CVE-2026-55204 was published for a high-severity denial-of-service vulnerability in HAProxy's HPACK handling. The flaw can be triggered remotely under memory pressure to crash worker processes and affects HAProxy through version 3.4.0.

CVE-2026-55204 - HAProxy - NULL Pointer Dereference in hpack_dht_insert Function

CVE-2026-55203 published for HAProxy FastCGI integer overflow

CVE-2026-55203 was published for a critical integer overflow vulnerability in HAProxy's FastCGI handling logic. The issue is remotely exploitable and affects HAProxy through version 3.4.0.

CVE-2026-55203 - HAProxy - Integer Overflow in FCGI Demux Record Length Field

HAProxy fixes HPACK NULL dereference in commit 9a6d1fe

HAProxy fixed a NULL pointer dereference in hpack_dht_insert() caused by not validating the return value of hpack_dht_defrag() under memory pressure. The issue could allow a remote attacker to crash HAProxy worker processes and affects HAProxy through version 3.4.0.

CVE-2026-55204 - HAProxy - NULL Pointer Dereference in hpack_dht_insert Function

HAProxy fixes FastCGI integer overflow in commit 5985276

HAProxy fixed an integer overflow in the FastCGI demux record length handling that could let a malicious FastCGI backend desynchronize parsing and cause request routing errors, response smuggling, or memory safety issues. The flaw affects HAProxy through version 3.4.0.

HAProxy - Integer Overflow in FCGI Demux Record Length Field | Advisories | VulnCheck
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Affected products
1 linked
Haproxy
Organizations
3 linked
Haproxycvefeed.ioVulnCheck
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.