
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26080 is a denial-of-service vulnerability in HAProxy caused by improper handling of variable-length integers (varint), which can cause the proxy to enter an infinite loop or crash. It affects HAProxy Community Edition versions 3.2.x (before 3.2.12) and 3.3.x (before 3.3.3), as well as HAProxy Enterprise and ALOHA products. The vulnerability was published on July 20, 2026, with a patch available in the same release cycle. It carries a CVSS v3.1 base score of 3.7 (Low) (GitHub Advisory).
The root cause is classified as CWE-252 (Unchecked Return Value): HAProxy fails to properly validate the return value when processing varint-encoded data, leading to a mishandled state that can trigger an infinite loop or process crash. The attack vector is network-accessible with no authentication or user interaction required, though high attack complexity limits exploitability. A fix commit is publicly referenced in the HAProxy 3.2 git repository (GitHub Advisory, HAProxy Commit).
Successful exploitation results in a low availability impact — specifically, HAProxy may enter a loop or crash, causing a partial denial of service for traffic being proxied through the affected instance. There is no impact on confidentiality or integrity. The scope is unchanged, meaning the impact is confined to the HAProxy process itself and does not enable lateral movement or data exfiltration (GitHub Advisory).
Users should upgrade HAProxy Community Edition to version 3.2.12 or 3.3.3 or later, which contain the fix for the varint mishandling issue. HAProxy Enterprise and ALOHA users should apply the corresponding vendor-supplied patches. No specific configuration-based workaround has been publicly documented; upgrading is the recommended remediation (GitHub Advisory, HAProxy Commit).
HAProxy published a blog post covering QUIC-related CVEs for 2026, which includes this vulnerability (HAProxy Blog). OpenSUSE and SUSE issued security advisories and package updates addressing this CVE (Linux Security). Tenable released a Nessus detection plugin (ID 300391) for this vulnerability (Tenable). No significant social media discussion or notable independent researcher commentary has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."