CVE-2026-55204Disclosure(haproxy / haproxy)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haproxy haproxy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • haproxy

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
haproxy

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-19: 1Mentions · 2026-06-23: 1Mentions · 2026-06-29: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-29: 106-1906-2306-29
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-191
Disclosure1
2026-06-231
Patch1
2026-06-291
General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-55204 Null Pointer Dereference in HAProxy Through 3.4.0 Causing Denial of Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-55204

    Post summary

    The post announces a null pointer dereference DoS vulnerability (CVE‑2026‑55204) in HAProxy up to 3.4.0, with no evidence of PoC, exploitation, or patch.

    0001162
    4.1K followersView on X
  • Autumn Good@autumn_good_35
    General

    『We want to be transparent about that score and equally clear about our assessment: the real-world risk is low. This is not realistically exploitable.』 June 2026 – CVE-2026-55204: null pointer dereference in HAProxy's HPACK header handling https://www.haproxy.com/blog/june-2026-cve-2026-55204-null-pointer-dereference-in-haproxys-hpack-header-handling

    Post summary

    The passage states that CVE‑2026‑55204, a null pointer dereference in HAProxy’s HPACK handling, presents low real‑world risk and is not realistically exploitable, without providing PoC, exploit, patch, or false‑positive information.

    00000415
    6.9K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    HAProxyに重大(Critical)な脆弱性。CVE-2026-55203はCVSSv4スコア9.0で、FCGIのDemuxレコード長における整数オーバーフロー。hpack_dht_insert関数におけるヌルポインタ参照(CVE-2026-55204、CVSSv4スコア8.7)もあり、それぞれ別コミットで修正。 https://securityonline.info/haproxy-vulnerabilities-cve-2026-55203/

    Post summary

    HAProxy has two critical CVEs (CVE-2026-55203 and CVE-2026-55204) involving an integer overflow and a null pointer dereference respectively, each fixed in separate commits; a link to more details is provided.

    00000776
    7.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaproxyhaproxy---

Explore more