{"id":"AZL-90261","summary":"CVE-2026-55204 affecting package haproxy for versions less than 2.9.11-7","details":"HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.","modified":"2026-08-29T05:27:27Z","published":"2026-06-18T17:16:34Z","upstream":["CVE-2026-55204"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55204"}],"affected":[{"package":{"name":"haproxy","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/haproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.11-7"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90261.json"}}],"schema_version":"1.9.0"}