Integer Overflow Vulnerability in HAProxy FCGI Record Processing
CVE-2026-55203

9CRITICAL

Key Information:

Vendor

Haproxy

Status
Vendor
CVE Published:
18 June 2026

What is CVE-2026-55203?

HAProxy prior to version 3.4.0 contains an integer overflow vulnerability in the fcgi_conn structure that affects the drl field. When the contentLength is set to 65535 and paddingLength is greater than or equal to 1, the drl field erroneously wraps to 0, leading to improper processing of FCGI records. This flaw can enable malicious FastCGI backends to disrupt the synchronization of the FCGI framing parser, potentially leading to request routing issues, response smuggling threats, or significant memory safety vulnerabilities.

Affected Version(s)

haproxy 0 <= 3.4.0

haproxy 5985276735777634d8c85f1d73bb7764aab0d6dd

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani (@TristanInSec)
.