On 29 June 2026, the French national CERT announced a remote denial‑of‑service vulnerability in HAProxy (CVE‑2026‑55204) caused by a null‑pointer dereference in the HPack header handling routine. The flaw can be triggered by an attacker sending specially crafted traffic that leads the software to crash. The vulnerability was identified in HAProxy’s handling of HPACK headers, a protocol used for compressed HTTP/2 headers. Affected releases include Aloha 14.5.x through 18.0.x versions prior to the listed patches, all Community Edition releases, and multiple Enterprise “hapee” builds before specific release numbers. Affected Aloha releases are enumerated with their patch thresholds in the CERT‑FR bulletin. CERT‑FR directs users to the HAProxy security bulletin dated 26 June 2026 for the correct patch or upgrade recommendation. Users should verify their HAProxy version and apply the vendor’s recommended update as soon as possible. No additional mitigation steps are provided in the notice.
Summary of content from
Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.