[ALSA-2026:55772] Important: haproxy security update
Type:
security
Severity:
important
Release date:
2026-08-18
Description:
The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications. Security Fix(es): * haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions (CVE-2026-55204) * haproxy: HAProxy: Response smuggling due to integer overflow in FastCGI record length handling (CVE-2026-55203) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 haproxy-2.8.14-3.el9_8.2.aarch64.rpm ac25cab345de8cbc0326fe074ebf25da5752dd5c09b1ed7fd84f4bc74e520af1
ppc64le haproxy-2.8.14-3.el9_8.2.ppc64le.rpm 6ca9b70d854cb242344f329cea960fdf2b933cff73c296232f37f96162d325e7
s390x haproxy-2.8.14-3.el9_8.2.s390x.rpm 01ef72f42f6a398e19f1476a726782574ccb8b99c096105ec6d5cf65de385fe5
x86_64 haproxy-2.8.14-3.el9_8.2.x86_64.rpm e1ddbb16b15f435cc2751ea38fb8ae2c7e111e61329096818b4d2aa2babf6df4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.