critical · CVSS v3 9.1
CVE-2026-93564
HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak allows memory exhaustion. The flaw resides in the handling of nested TLV
Overview
HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak allows memory exhaustion. The flaw resides in the handling of nested TLVs in the PROXY protocol. It can lead to denial of service on affected HAProxy instances.
Description
HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)
Impact
The vulnerability can cause a denial of service by exhausting memory, potentially leading to service interruption. It affects HAProxy deployments that enable the PROXY-v2 protocol. Defenders should be aware that attackers could trigger repeated malformed packets to deplete resources.
Remediation
Apply the latest HAProxy release that includes the reference-count fix (e.g., 2.8.12 or newer). If upgrading is not immediately possible, disable the PROXY-v2 protocol or restrict its use to trusted sources. Monitor memory usage and set limits on HAProxy processes to mitigate impact.
Risk context
Severity is critical with a CVSS v3 score of 9.1. No EPSS data is available, but the high severity indicates a high likelihood of exploitation in active networks.
Affected products
- HAProxy
Scores
- Severity
- critical
- CVSS v2
- 7.8
- CVSS v3
- 9.1
- CVSS v4
- —
- EPSS
- —