DEBIAN-CVE-2026-55203

Source
https://security-tracker.debian.org/tracker/CVE-2026-55203
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-55203.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-55203
Upstream
Published
2026-06-18T17:16:34Z
Modified
2026-09-14T17:03:19Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

References

Affected packages

Debian:12 / haproxy

Package

Name
haproxy
Purl
pkg:deb/debian/haproxy?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.12-1
2.6.12-1+deb12u1
2.6.12-1+deb12u2
2.6.12-1+deb12u3
2.6.13-1
2.6.14-1
2.6.15-1
2.7.0-1
2.7.1-1
2.7.2-1
2.7.2-2
2.7.3-1
2.7.4-1
2.7.5-1
2.7.6-1
2.7.7-1
2.7.8-1
2.8.0-1
2.8.1-1
2.8.2-1
2.8.3-1
2.8.4-1
2.8.4-2
2.8.5-1
2.9.0-1
2.9.1-1
2.9.2-1
2.9.3-1
2.9.4-1
2.9.5-1
2.9.6-1
2.9.7-1
2.9.8-1
2.9.9-1
2.9.10-1
2.9.11-1
2.9.12-1
3.*
3.0.0-1
3.0.1-1
3.0.2-1
3.0.3-1
3.0.4-1
3.0.5-1
3.0.6-1
3.0.6-2
3.0.6-3
3.0.7-1
3.0.8-1
3.0.9-1
3.0.10-1
3.0.11-1
3.1.0-1
3.1.0-2
3.1.1-1
3.1.2-1
3.1.3-1
3.1.5-1
3.1.6-1
3.1.7-1
3.2.0-1
3.2.1-1
3.2.3-1
3.2.3-2
3.2.4-1
3.2.5-1
3.2.5-2
3.2.6-1
3.2.7-1
3.2.8-1
3.2.9-1
3.2.10-1
3.2.11-1
3.2.11-2
3.2.12-1
3.2.13-1
3.2.14-1
3.2.15-1
3.2.16-1
3.2.17-1
3.2.18-1
3.2.19-1
3.2.20-1
3.2.21-1
3.2.22-1
3.2.23-1
3.3.0-1
3.3.1-1
3.3.2-1
3.3.2-2
3.3.3-1
3.3.4-1
3.3.5-1
3.3.6-1
3.3.7-1
3.3.8-1
3.3.9-1
3.3.10-1
3.4.0-1
3.4.1-1
3.4.2-1
3.4.3-1
3.4.4-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-55203.json"

Debian:13 / haproxy

Package

Name
haproxy
Purl
pkg:deb/debian/haproxy?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.11-1
3.0.11-1+deb13u1
3.0.11-1+deb13u2
3.0.11-1+deb13u3
3.1.0-1
3.1.0-2
3.1.1-1
3.1.2-1
3.1.3-1
3.1.5-1
3.1.6-1
3.1.7-1
3.2.0-1
3.2.1-1
3.2.3-1
3.2.3-2
3.2.4-1
3.2.5-1
3.2.5-2
3.2.6-1
3.2.7-1
3.2.8-1
3.2.9-1
3.2.10-1
3.2.11-1
3.2.11-2
3.2.12-1
3.2.13-1
3.2.14-1
3.2.15-1
3.2.16-1
3.2.17-1
3.2.18-1
3.2.19-1
3.2.20-1
3.2.21-1
3.2.22-1
3.2.23-1
3.3.0-1
3.3.1-1
3.3.2-1
3.3.2-2
3.3.3-1
3.3.4-1
3.3.5-1
3.3.6-1
3.3.7-1
3.3.8-1
3.3.9-1
3.3.10-1
3.4.0-1
3.4.1-1
3.4.2-1
3.4.3-1
3.4.4-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-55203.json"

Debian:14 / haproxy

Package

Name
haproxy
Purl
pkg:deb/debian/haproxy?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.2.20-1

Affected versions

3.*
3.0.11-1
3.1.0-1
3.1.0-2
3.1.1-1
3.1.2-1
3.1.3-1
3.1.5-1
3.1.6-1
3.1.7-1
3.2.0-1
3.2.1-1
3.2.3-1
3.2.3-2
3.2.4-1
3.2.5-1
3.2.5-2
3.2.6-1
3.2.7-1
3.2.8-1
3.2.9-1
3.2.10-1
3.2.11-1
3.2.11-2
3.2.12-1
3.2.13-1
3.2.14-1
3.2.15-1
3.2.16-1
3.2.17-1
3.2.18-1
3.2.19-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-55203.json"