CVE-2026-55203

EUVD-2026-37905
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
haproxyhaproxy
𝑥
≤ 3.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
haproxy
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
3.2.22-1
fixed
sid
3.2.22-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
haproxy
bionic
needs-triage
focal
needs-triage
jammy
Fixed 2.4.30-0ubuntu0.22.04.2
released
noble
Fixed 2.8.16-0ubuntu0.24.04.3
released
questing
Fixed 3.0.12-0ubuntu0.25.10.5
released
resolute
Fixed 3.2.9-1ubuntu2.2
released
xenial
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
haproxy
Azure Linux 3.0
0:2.9.11-7.azl3
fixed