Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55204

Опубликовано: 18 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

A flaw was found in HAProxy. An attacker can trigger HPACK dynamic table insertions under memory pressure, leading to a null pointer dereference in the hpack_dht_insert() function. This can cause HAProxy worker processes to crash, resulting in a denial of service (DoS).

Отчет

This Important flaw in HAProxy can lead to a denial of service. An unauthenticated remote attacker could exploit a null pointer dereference by triggering HPACK dynamic table insertions under memory pressure, causing HAProxy worker processes to crash. This impacts the availability of services relying on HAProxy as a load balancer or proxy.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5rhceph/rhceph-haproxy-rhel8Affected
Red Hat Ceph Storage 6rhceph/rhceph-haproxy-rhel9Affected
Red Hat Ceph Storage 7rhceph/rhceph-haproxy-rhel9Affected
Red Hat Ceph Storage 8rhceph/rhceph-haproxy-rhel9Affected
Red Hat Ceph Storage 9rhceph-ci/haproxyAffected
Red Hat Ceph Storage 9rhceph/rhceph-haproxy-rhel10Affected
Red Hat Ceph Storage 9rhceph/rhceph-haproxy-rhel9Affected
Red Hat Enterprise Linux 10haproxyAffected
Red Hat Enterprise Linux 7haproxyOut of support scope
Red Hat Enterprise Linux 8haproxyAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2490518haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

CVSS3: 7.5
nvd
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

CVSS3: 7.5
msrc
около 1 месяца назад

HAProxy - NULL Pointer Dereference in hpack_dht_insert Function

CVSS3: 7.5
debian
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null point ...

CVSS3: 7.5
github
около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

7.5 High

CVSS3