[ALSA-2026:55679] Important: haproxy security update
Type:
security
Severity:
important
Release date:
2026-08-18
Description:
The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications. Security Fix(es): * haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions (CVE-2026-55204) * haproxy: HAProxy: Response smuggling due to integer overflow in FastCGI record length handling (CVE-2026-55203) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 haproxy-3.0.5-6.el10_2.2.aarch64.rpm d9295cc2a61e85ee59a4f02c87e92a43dc8504cf0768aa8423f1fbe15f7c6d0c
ppc64le haproxy-3.0.5-6.el10_2.2.ppc64le.rpm 373d6ff1d2138d0b20f583215022a4c011687f6beeac3cf4dbf2515a3549afbb
s390x haproxy-3.0.5-6.el10_2.2.s390x.rpm 7994ea2ac53cffa8af6ec2bd11cc6103e0b4e6040b98ce7fa7c28943a2e0b305
x86_64 haproxy-3.0.5-6.el10_2.2.x86_64.rpm a69ec555334c0106e2835c3f051e38aa34e9ab34528b50b2a0242f804f987141
x86_64_v2 haproxy-3.0.5-6.el10_2.2.x86_64_v2.rpm c6b86236d5a68f5b208e9b5ee8ffd65cc181a06b527ab4e477076b9cfd2c6612
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.