Junglewise Threat Intelligence

CVE-2026-26081: HAProxy missing length check in NEW_TOKEN format handling

CVE-2026-26081 · Severity: medium · CVSS 4.8 · Published 2026-07-20

Vendors: HAProxy.

Executive brief

HAProxy is a high-performance load balancer used to distribute web traffic and ensure application availability. A vulnerability in how it handles certain network tokens could allow an attacker to send specially crafted data packets that crash the service. This would result in a service outage, preventing legitimate users from accessing the applications protected by HAProxy.

Technical details

A vulnerability exists in HAProxy versions 3.0 through 3.3 (before 3.3.3) due to an improper handling of the length parameter (CWE-130) within the NEW_TOKEN format, specifically affecting QUIC parsing. An attacker can exploit this by sending specially crafted network packets to the HAProxy instance. Successful exploitation can lead to a process crash, resulting in a denial-of-service (DoS) condition. The vulnerability has been addressed in versions 3.0.12, 3.1.14, 3.2.12, and 3.3.3.

Affected products

  • HAProxy HAProxy Community Edition 3.0 before 3.0.12, 3.1 before 3.1.14, 3.2 before 3.2.12, 3.3 before 3.3.3
  • HAProxy HAProxy Enterprise
  • HAProxy ALOHA

Timeline

  • 2026-02-12: advisory: HAProxy project mentions the vulnerability in news updates
  • 2026-07-20: disclosed: CVE published to NVD dataset

References

Related threats