Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55203

Опубликовано: 18 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

A flaw was found in HAProxy. A malicious FastCGI (Fast Common Gateway Interface) backend can exploit an integer overflow vulnerability in the fcgi_conn structure's drl field. This occurs when specific contentLength and paddingLength values cause the drl field to wrap to zero, leading to incorrect record consumption. This desynchronizes the FCGI framing parser, potentially resulting in response smuggling, request routing errors, or memory safety issues.

Отчет

Conditions for Exploitation: Successful exploitation requires a specific configuration where HAProxy is actively utilizing a FastCGI backend. Crucially, an attacker must already have control over this backend server to supply the maliciously crafted responses. This requirement significantly restricts the attack vector, as it relies on an unlikely configuration or an already compromised backend, rather than a typical remote attack initiated by a client against a default frontend server. Impact Limitations: Although the vulnerability can cause the FastCGI framing parser to desynchronize—potentially leading to response smuggling, request routing errors, or memory safety issues—the threat is contained entirely to environments that process traffic from untrusted or compromised backend servers.

Меры по смягчению последствий

To mitigate this issue, restrict access to HAProxy instances that utilize FastCGI to trusted FastCGI backends only. If FastCGI is not required, consider disabling its use in HAProxy configurations to eliminate the attack vector. Ensure that all FastCGI backends are secured and not susceptible to compromise. If the HAProxy service is reloaded or restarted after configuration changes, ensure proper validation of the new configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5rhceph/rhceph-haproxy-rhel8Affected
Red Hat Ceph Storage 6rhceph/rhceph-haproxy-rhel9Affected
Red Hat Ceph Storage 7rhceph/rhceph-haproxy-rhel9Affected
Red Hat Ceph Storage 8rhceph/rhceph-haproxy-rhel9Affected
Red Hat Ceph Storage 9rhceph-ci/haproxyAffected
Red Hat Ceph Storage 9rhceph/rhceph-haproxy-rhel10Affected
Red Hat Ceph Storage 9rhceph/rhceph-haproxy-rhel9Affected
Red Hat Enterprise Linux 10haproxyAffected
Red Hat Enterprise Linux 7haproxyOut of support scope
Red Hat Enterprise Linux 8haproxyAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2490522haproxy: HAProxy: Response smuggling due to integer overflow in FastCGI record length handling

EPSS

Процентиль: 27%
0.00347
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
nvd
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
msrc
около 1 месяца назад

HAProxy - Integer Overflow in FCGI Demux Record Length Field

CVSS3: 7.5
debian
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ov ...

CVSS3: 7.5
github
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

EPSS

Процентиль: 27%
0.00347
Низкий

7.5 High

CVSS3