CVE-2026-55203High· 7.5▾ TwilightHAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
haproxy < 2.4.36haproxy >= 2.5, < 2.6.30haproxy >= 2.7, < 2.8.25haproxy >= 2.9, < 3.0.24haproxy >= 3.1, < 3.2.20haproxy >= 3.3, < 3.4.1Upgrade past the affected range:
haproxy 3.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55204High· 7.5HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhaust…
CVE-2026-33555Medium· 4.0An issue was discovered in HAProxy before 3.3.6
CVE-2022-2285High· 7.8Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
CVE-2021-3520Critical· 9.8There's a flaw in lz4
CVE-2026-43618High· 8.1Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receive…
CVE-2026-2921High· 7.8GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability