RHSA-2026:55860: Important: haproxy security update
The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications.Security Fix(es): haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions (CVE-2026-55204) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/haproxyto a version that resolves this vulnerability.Fixed in 1.8.27-5.el8_8.2 - Upgrade
Upgrade
redhat/haproxy-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.27-5.el8_8.2 - Upgrade
Upgrade
redhat/haproxy-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.27-5.el8_8.2
Event History
Frequently Asked Questions
Which deployments should be prioritized for this update?
Systems using the Red Hat HAProxy packages listed in the advisory are in scope, including the haproxy, haproxy-debuginfo, and haproxy-debugsource packages. The issue is rated Important by Red Hat.
What is known about exploitation requirements and temporary mitigations?
The flaw is a denial-of-service issue involving HPACK dynamic table insertions. The advisory does not state the required attacker access, affected configuration conditions, or any workaround when patching cannot be performed immediately.