rootpwn

critical · CVSS v3 9.1

CVE-2026-93564

HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak allows memory exhaustion. The flaw resides in the handling of nested TLV

Overview

HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak allows memory exhaustion. The flaw resides in the handling of nested TLVs in the PROXY protocol. It can lead to denial of service on affected HAProxy instances.

Description

HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)

Impact

The vulnerability can cause a denial of service by exhausting memory, potentially leading to service interruption. It affects HAProxy deployments that enable the PROXY-v2 protocol. Defenders should be aware that attackers could trigger repeated malformed packets to deplete resources.

Remediation

Apply the latest HAProxy release that includes the reference-count fix (e.g., 2.8.12 or newer). If upgrading is not immediately possible, disable the PROXY-v2 protocol or restrict its use to trusted sources. Monitor memory usage and set limits on HAProxy processes to mitigate impact.

Risk context

Severity is critical with a CVSS v3 score of 9.1. No EPSS data is available, but the high severity indicates a high likelihood of exploitation in active networks.

Affected products

  • HAProxy

Scores

Severity
critical
CVSS v2
7.8
CVSS v3
9.1
CVSS v4
EPSS

ha-proxy reference-count memory-leak critical denial-of-service network-proxy

← All CVEs