Junglewise Threat Intelligence

CVE-2026-55204: HAProxy NULL pointer dereference in hpack_dht_insert

CVE-2026-55204 · Severity: high · CVSS 7.5 · Published 2026-06-18

Technologies: HAProxy. Vendors: HAProxy.

Executive brief

HAProxy is a widely used load balancer and proxy server that manages web traffic for high-availability environments. A flaw in how it handles compressed web headers can allow a remote attacker to crash the service by sending specific requests during periods of high memory usage. This results in a denial-of-service (DoS) condition, potentially taking websites or applications offline.

Technical details

A NULL pointer dereference exists in the hpack_dht_insert() function within src/hpack-tbl.c. The vulnerability occurs because the code fails to validate the return value of hpack_dht_defrag() when the memory pool (pool_head_hpack_tbl) is exhausted. An attacker can exploit this by triggering HPACK dynamic table insertions under memory pressure, leading the application to dereference a NULL pointer plus an offset. This results in a SIGSEGV and a crash of the HAProxy worker process. The issue is fixed in commit 9a6d1fe and affects versions through 3.4.0.

Affected products

  • HAProxy HAProxy Up to and including 3.4.0

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References

Related threats