securityonline.info 6/23/2026, 2:32:00 AM · external

HAProxy flaws enable response smuggling denial of service attacks

HAProxy flaws enable response smuggling denial of service attacks
CyberSIXT Evidence Panel
Primary Source vulncheck.com
CISA KEV Not in KEV
Patch Patch Available

HAPROXY has two critical vulnerabilities: CVE-2026-55203 (Integer Overflow) and CVE-2026-55204 (NULL Pointer Dereference), with severities of 9.0 and 8.7, respectively. The integer overflow issue allows for response smuggling, while the null pointer dereference can lead to denial of service. Both vulnerabilities affect versions up to 3.4.0. Although no confirmed exploitation has occurred, patches have been released, and administrators are urged to update to secure their systems.

View Primary Source Via securityonline.info

Article by CyberSIXT