HAProxy PROXY-v2 Vulnerability Related to ByteBuf Reference Count Leak
CVE-2026-93564

7.5HIGH

What is CVE-2026-93564?

The HAProxy PROXY-v2 component is affected by a vulnerability characterized by a nested-TLV grandchild ByteBuf reference-count leak. This issue stems from an incomplete fix applied previously, leaving the system exposed to potential resource management inefficiencies. Administrators should assess their HAProxy configurations and apply any available patches to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.