CVE-2026-55204High· 7.5▾ TwilightHAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhaust…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
haproxy < 2.4.36haproxy >= 2.5, < 2.6.30haproxy >= 2.7, < 2.8.25haproxy >= 2.9, < 3.0.24haproxy >= 3.1, < 3.2.20haproxy >= 3.3, < 3.4.1Upgrade past the affected range:
haproxy 3.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55203High· 7.5HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers
CVE-2026-33555Medium· 4.0An issue was discovered in HAProxy before 3.3.6
CVE-2022-1674Medium· 5.5NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938
CVE-2022-1620High· 7.5NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901
CVE-2023-4459Medium· 5.5A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel
CVE-2025-11550Medium· 6.5A vulnerability was found in Tenda W12 3.0.0.6(3948)