---
id: CVE-2026-55204
title: >-
  HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer
  dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that
  fails to validate the return value of hpack_dht_defrag() when the memory pool
  is exhaust…
summary: >-
  HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer
  dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that
  fails to validate the return value of hpack_dht_defrag() when the memory pool
  is exhaust…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: haproxy
product: haproxy
affected:
  - haproxy < 2.4.36
  - 'haproxy >= 2.5, < 2.6.30'
  - 'haproxy >= 2.7, < 2.8.25'
  - 'haproxy >= 2.9, < 3.0.24'
  - 'haproxy >= 3.1, < 3.2.20'
  - 'haproxy >= 3.3, < 3.4.1'
patched:
  - haproxy 3.4.1
published: '2026-06-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T17:13:02.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55204'
references:
  - url: >-
      https://github.com/haproxy/haproxy/commit/9a6d1fe3f00d86ab4ea6ea6ea0a5d48fc058a513
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/haproxy-null-pointer-dereference-in-hpack-dht-insert-function
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00484
epssPercentile: 0.3971
ingestedAt: '2026-10-08T17:56:11.697Z'
---

## Overview

HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

## Affected

- `haproxy < 2.4.36`
- `haproxy >= 2.5, < 2.6.30`
- `haproxy >= 2.7, < 2.8.25`
- `haproxy >= 2.9, < 3.0.24`
- `haproxy >= 3.1, < 3.2.20`
- `haproxy >= 3.3, < 3.4.1`

## Remediation

Upgrade past the affected range:

- `haproxy 3.4.1`
