CVE-2026-55204

EUVD-2026-37906
HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
haproxyhaproxy
𝑥
≤ 3.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
haproxy
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
3.2.22-1
fixed
sid
3.2.22-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
haproxy
bionic
needs-triage
focal
needs-triage
jammy
Fixed 2.4.30-0ubuntu0.22.04.2
released
noble
Fixed 2.8.16-0ubuntu0.24.04.3
released
questing
Fixed 3.0.12-0ubuntu0.25.10.5
released
resolute
Fixed 3.2.9-1ubuntu2.2
released
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
haproxy
Amazon Linux 2023
0:3.0.23-2.amzn2023.0.1
fixed
haproxy-debuginfo
Amazon Linux 2023
0:3.0.23-2.amzn2023.0.1
fixed
haproxy-debugsource
Amazon Linux 2023
0:3.0.23-2.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
haproxy
Azure Linux 3.0
0:2.9.11-7.azl3
fixed