Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-55203

около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-55203

около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-55203

около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-55203

около 1 месяца назад

HAProxy - Integer Overflow in FCGI Demux Record Length Field

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-55203

около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ov ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-58mj-cmhg-35rg

около 2 месяцев назад

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21245-1

27 дней назад

Security update for haproxy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2652-1

около 1 месяца назад

Security update for haproxy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2651-1

около 1 месяца назад

Security update for haproxy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
msrc логотип
CVE-2026-55203

HAProxy - Integer Overflow in FCGI Demux Record Length Field

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ov ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-58mj-cmhg-35rg

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21245-1

Security update for haproxy

27 дней назад
suse-cvrf логотип
SUSE-SU-2026:2652-1

Security update for haproxy

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2651-1

Security update for haproxy

около 1 месяца назад

Уязвимостей на страницу