CVE-2026-26080
HAProxy vulnerability analysis and mitigation

Overview

CVE-2026-26080 is a denial-of-service vulnerability in HAProxy caused by improper handling of variable-length integers (varint), which can cause the proxy to enter an infinite loop or crash. It affects HAProxy Community Edition versions 3.2.x (before 3.2.12) and 3.3.x (before 3.3.3), as well as HAProxy Enterprise and ALOHA products. The vulnerability was published on July 20, 2026, with a patch available in the same release cycle. It carries a CVSS v3.1 base score of 3.7 (Low) (GitHub Advisory).

Technical details

The root cause is classified as CWE-252 (Unchecked Return Value): HAProxy fails to properly validate the return value when processing varint-encoded data, leading to a mishandled state that can trigger an infinite loop or process crash. The attack vector is network-accessible with no authentication or user interaction required, though high attack complexity limits exploitability. A fix commit is publicly referenced in the HAProxy 3.2 git repository (GitHub Advisory, HAProxy Commit).

Impact

Successful exploitation results in a low availability impact — specifically, HAProxy may enter a loop or crash, causing a partial denial of service for traffic being proxied through the affected instance. There is no impact on confidentiality or integrity. The scope is unchanged, meaning the impact is confined to the HAProxy process itself and does not enable lateral movement or data exfiltration (GitHub Advisory).

Mitigation and workarounds

Users should upgrade HAProxy Community Edition to version 3.2.12 or 3.3.3 or later, which contain the fix for the varint mishandling issue. HAProxy Enterprise and ALOHA users should apply the corresponding vendor-supplied patches. No specific configuration-based workaround has been publicly documented; upgrading is the recommended remediation (GitHub Advisory, HAProxy Commit).

Community reactions

HAProxy published a blog post covering QUIC-related CVEs for 2026, which includes this vulnerability (HAProxy Blog). OpenSUSE and SUSE issued security advisories and package updates addressing this CVE (Linux Security). Tenable released a Nessus detection plugin (ID 300391) for this vulnerability (Tenable). No significant social media discussion or notable independent researcher commentary has been identified.

Additional resources


SourceThis report was generated using AI

Related HAProxy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55203CRITICAL9
  • HAProxy logoHAProxy
  • haproxy-3.4
NoYesJun 18, 2026
CVE-2026-55204HIGH8.7
  • HAProxy logoHAProxy
  • haproxy-debuginfo
NoYesJun 18, 2026
CVE-2026-33555MEDIUM5.8
  • HAProxy logoHAProxy
  • haproxy-2.8
NoYesApr 13, 2026
CVE-2026-26081MEDIUM4.8
  • HAProxy logoHAProxy
  • cpe:2.3:a:haproxy:haproxy
NoYesJul 20, 2026
CVE-2026-26080LOW3.7
  • HAProxy logoHAProxy
  • cpe:2.3:a:haproxy:haproxy
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management