{"id":"CVE-2026-55204","title":"HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhaust…","summary":"HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhaust…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"haproxy","product":"haproxy","affected":["haproxy < 2.4.36","haproxy >= 2.5, < 2.6.30","haproxy >= 2.7, < 2.8.25","haproxy >= 2.9, < 3.0.24","haproxy >= 3.1, < 3.2.20","haproxy >= 3.3, < 3.4.1"],"patched":["haproxy 3.4.1"],"published":"2026-06-18","updated":"2026-10-08","sourceUpdated":"2026-10-08T17:13:02.447","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55204","references":[{"url":"https://github.com/haproxy/haproxy/commit/9a6d1fe3f00d86ab4ea6ea6ea0a5d48fc058a513","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/haproxy-null-pointer-dereference-in-hpack-dht-insert-function","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00484,"epssPercentile":0.3971,"ingestedAt":"2026-10-08T17:56:11.697Z","slug":"CVE-2026-55204","body":"## Overview\n\nHAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.\n\n## Affected\n\n- `haproxy < 2.4.36`\n- `haproxy >= 2.5, < 2.6.30`\n- `haproxy >= 2.7, < 2.8.25`\n- `haproxy >= 2.9, < 3.0.24`\n- `haproxy >= 3.1, < 3.2.20`\n- `haproxy >= 3.3, < 3.4.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `haproxy 3.4.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}