🛡️ MGASA-2026-0250 — haproxy

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Updated haproxy packages fix security vulnerability

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow

vulnerability in the fcgi_conn structure's drl field that allows buffer

misparse as new FCGI record headers. When contentLength is 65535 and

paddingLength is 1 or more, the drl field wraps to 0, causing incorrect

record consumption and allowing malicious FastCGI backends to desynchronize

the FCGI framing parser, potentially causing request routing errors, response

smuggling, or memory safety issues.

(CVE-2026-55203)

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer

dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that

fails to validate the return value of hpack_dht_defrag() when the memory pool

is exhausted. An attacker can trigger HPACK dynamic table insertions under

memory pressure to dereference a NULL pointer and crash HAProxy worker

processes, causing denial of service.

(CVE-2026-55204)

Affected software

MGASA-2026-0250 is recorded against 1 package.

  • haproxy (fixed in 2.8.26-1.mga9)

Timeline and source

Published on 14 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

advisories.mageia.org (Advisory)
bugs.mageia.org (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-14
Updated 2026-08-12
Modified 2026-07-14
Fix URL N/A

Affected Packages

Software From version Fixed in
haproxy 2.8.26-1.mga9

Similar Threats

Free Vulnerability Check

Is your site affected by MGASA-2026-0250?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2026-0250 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesMageiaMageia 2026