Junglewise Threat Intelligence

CVE-2026-55203: HAProxy integer overflow in FCGI demultiplexer

CVE-2026-55203 · Severity: high · CVSS 7.5 · Published 2026-06-18

Technologies: HAProxy. Vendors: HAProxy.

Executive brief

HAProxy, a popular high-performance load balancer and proxy server, contains a vulnerability in how it handles communication with FastCGI backends. A malicious or compromised backend server could send specially crafted data that causes HAProxy to misinterpret where one message ends and the next begins. This could lead to response smuggling, where an attacker can manipulate web traffic, potentially bypassing security controls or causing data to be routed to the wrong user.

Technical details

An integer overflow vulnerability exists in the fcgi_conn structure's drl (demux record length) field in HAProxy through 3.4.0. The field is defined as a uint16_t; when processing a FastCGI record with a contentLength of 65535 and a paddingLength of 1 or more, the addition of these values causes the field to wrap to 0. This leads the state machine to believe a record is complete without consuming the buffer data, causing subsequent data to be misparsed as new FCGI record headers. An attacker controlling a FastCGI backend can exploit this to desynchronize the parser, enabling response smuggling or request routing errors. The issue is fixed by widening the drl field to uint32_t in commit 5985276.

Affected products

  • HAProxy HAProxy through 3.4.0

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory
  • 2026-06-18: patched: Fixed in commit 5985276

References

Related threats