What is CVE-2026-55203?
HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
The record classifies CVE-2026-55203 under weakness class CWE-190. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction, and has high impact on integrity. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 109 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 7.5 — HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N - CVSS v4.0 base score
- 9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N - CISA KEV
- Not listed in the CISA Known Exploited Vulnerabilities catalog
- Threadlinqs priority
- 3.8/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- Published
- 2026-06-18
Is CVE-2026-55203 being exploited?
It currently carries a trending score of 30 in the Threadlinqs vulnerability feed.
Affected products and versions
- haproxy: haproxy
How to fix CVE-2026-55203
No vendor patch reference has been recorded for CVE-2026-55203 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.
Threat activity tracking CVE-2026-55203
No threat campaign in the Threadlinqs corpus currently references CVE-2026-55203, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.
Sources
Enriched from CVE.org, GitHub Security Advisories. Last verified by Threadlinqs on .