CVE-2026-93564

A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a Denial of Service (DoS) for the affected system.

  • Published Sep 18, 2026
  • CVSS 7.5 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-93564 at the National Vulnerability Database