HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues. | |
| Title | HAProxy - Integer Overflow in FCGI Demux Record Length Field | |
| First Time appeared |
Haproxy
Haproxy aloha |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:haproxy:aloha:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Haproxy
Haproxy aloha |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-18T16:05:20.100Z
Reserved: 2026-06-16T15:53:37.764Z
Link: CVE-2026-55203
No data.
No data.
No data.
OpenCVE Enrichment
No data.