RHSA-2026:55802: Important: haproxy security update
The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications.Security Fix(es): haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions (CVE-2026-55204) haproxy: HAProxy: Response smuggling due to integer overflow in FastCGI record length handling (CVE-2026-55203) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/haproxyto a version that resolves this vulnerability.Fixed in 2.4.17-6.el9_2.5 - Upgrade
Upgrade
redhat/haproxy-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.17-6.el9_2.5 - Upgrade
Upgrade
redhat/haproxy-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.17-6.el9_2.5 - Upgrade
Upgrade
redhat/haproxyto a version that resolves this vulnerability.Fixed in 2.4.17-6.el9_2.5.aa - Upgrade
Upgrade
redhat/haproxy-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.17-6.el9_2.5.aa - Upgrade
Upgrade
redhat/haproxy-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.17-6.el9_2.5.aa - Upgrade
Upgrade
haproxyto a version that resolves this vulnerability.Patch CVE-2026-55203 - Upgrade
Upgrade
haproxyto a version that resolves this vulnerability.Patch CVE-2026-55204
Event History
Frequently Asked Questions
Which deployed software is covered by this update?
Systems using the listed Red Hat HAProxy packages are in scope: redhat/haproxy, redhat/haproxy-debuginfo, and redhat/haproxy-debugsource. The advisory identifies security fixes in HAProxy's HTTP/2 HPACK handling and FastCGI record-length handling.
What attack types are addressed?
The update addresses a denial-of-service condition involving HPACK dynamic-table insertions and a response-smuggling issue caused by an integer overflow when handling FastCGI record lengths. The provided advisory does not specify additional prerequisites, affected configurations, or exploit conditions.