Количество 21
Количество 21
openSUSE-SU-2026:21245-1
Security update for haproxy
SUSE-SU-2026:2652-1
Security update for haproxy
SUSE-SU-2026:2651-1
Security update for haproxy
RLSA-2026:55772
Important: haproxy security update
RLSA-2026:55679
Important: haproxy security update
ELSA-2026-55772
ELSA-2026-55772: haproxy security update (IMPORTANT)
ELSA-2026-55679
ELSA-2026-55679: haproxy security update (IMPORTANT)
CVE-2026-55203
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
CVE-2026-55203
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
CVE-2026-55203
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
CVE-2026-55203
HAProxy - Integer Overflow in FCGI Demux Record Length Field
CVE-2026-55203
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ov ...
CVE-2026-55204
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
CVE-2026-55204
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
CVE-2026-55204
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
CVE-2026-55204
HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
CVE-2026-55204
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null point ...
GHSA-58mj-cmhg-35rg
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
RLSA-2026:55859
Important: haproxy security update
GHSA-4vj2-5mvx-3vcc
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2026:21245-1 Security update for haproxy | 3 месяца назад | |||
SUSE-SU-2026:2652-1 Security update for haproxy | 3 месяца назад | |||
SUSE-SU-2026:2651-1 Security update for haproxy | 3 месяца назад | |||
RLSA-2026:55772 Important: haproxy security update | около 1 месяца назад | |||
RLSA-2026:55679 Important: haproxy security update | около 1 месяца назад | |||
ELSA-2026-55772 ELSA-2026-55772: haproxy security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-55679 ELSA-2026-55679: haproxy security update (IMPORTANT) | около 1 месяца назад | |||
CVE-2026-55203 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55203 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55203 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55203 HAProxy - Integer Overflow in FCGI Demux Record Length Field | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55203 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ov ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55204 HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55204 HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55204 HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55204 HAProxy - NULL Pointer Dereference in hpack_dht_insert Function | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55204 HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null point ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-58mj-cmhg-35rg HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
RLSA-2026:55859 Important: haproxy security update | 0% Низкий | около 1 месяца назад | ||
GHSA-4vj2-5mvx-3vcc HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу