High severity7.5NVD Advisory· Published Jun 18, 2026· Updated Jul 14, 2026
CVE-2026-55204
CVE-2026-55204
Description
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords12 versionspkg:apk/chainguard/haproxy-2.4pkg:apk/wolfi/haproxy-3.2pkg:apk/chainguard/haproxy-3.2pkg:rpm/opensuse/haproxy&distro=openSUSE%20Tumbleweedpkg:bitnami/haproxypkg:rpm/almalinux/haproxypkg:rpm/opensuse/haproxy&distro=openSUSE%20Leap%2016.0pkg:apk/chainguard/haproxy-2.8pkg:apk/wolfi/haproxy-3.3pkg:apk/chainguard/haproxy-2.6pkg:apk/chainguard/haproxy-3.0pkg:apk/chainguard/haproxy-3.3
< 2.4.36-r0+ 11 more
- (no CPE)range: < 2.4.36-r0
- (no CPE)range: < 3.2.20-r0
- (no CPE)range: < 3.2.20-r0
- (no CPE)range: < 3.4.0+git31.fc300e9f2-1.1
- (no CPE)range: < 3.4.1
- (no CPE)range: < 3.0.5-6.el10_2.2
- (no CPE)range: < 3.2.21+git0.dbe43be37-160000.1.1
- (no CPE)range: < 2.8.26-r0
- (no CPE)range: < 3.3.11-r0
- (no CPE)range: < 2.6.31-r0
- (no CPE)range: < 3.0.24-r0
- (no CPE)range: < 3.3.11-r0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.