High severity7.5NVD Advisory· Published Jun 18, 2026· Updated Jul 14, 2026
CVE-2026-55203
CVE-2026-55203
Description
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords12 versionspkg:apk/chainguard/haproxy-2.8pkg:apk/wolfi/haproxy-3.2pkg:apk/wolfi/haproxy-3.3pkg:apk/chainguard/haproxy-3.2pkg:apk/chainguard/haproxy-2.4pkg:rpm/almalinux/haproxypkg:apk/chainguard/haproxy-2.6pkg:apk/chainguard/haproxy-3.0pkg:rpm/opensuse/haproxy&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/haproxy-3.3pkg:rpm/opensuse/haproxy&distro=openSUSE%20Leap%2016.0pkg:bitnami/haproxy
< 2.8.26-r0+ 11 more
- (no CPE)range: < 2.8.26-r0
- (no CPE)range: < 3.2.20-r0
- (no CPE)range: < 3.3.11-r0
- (no CPE)range: < 3.2.20-r0
- (no CPE)range: < 2.4.36-r0
- (no CPE)range: < 3.0.5-6.el10_2.2
- (no CPE)range: < 2.6.31-r0
- (no CPE)range: < 3.0.24-r0
- (no CPE)range: < 3.4.0+git31.fc300e9f2-1.1
- (no CPE)range: < 3.3.11-r0
- (no CPE)range: < 3.2.21+git0.dbe43be37-160000.1.1
- (no CPE)range: < 3.4.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.