HAPROXY has two critical vulnerabilities: CVE-2026-55203 (Integer Overflow) and CVE-2026-55204 (NULL Pointer Dereference), with severities of 9.0 and 8.7, respectively. The integer overflow issue allows for response smuggling, while the null pointer dereference can lead to denial of service. Both vulnerabilities affect versions up to 3.4.0. Although no confirmed exploitation has occurred, patches have been released, and administrators are urged to update to secure their systems.
HAProxy flaws enable response smuggling denial of service attacks
CyberSIXT Evidence Panel
Article by CyberSIXT