
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26081 is a vulnerability in HAProxy Community Edition affecting versions 3.0 through 3.3 (before 3.3.3) caused by a missing length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. The vulnerability was published on July 20, 2026, and has a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory). Specific affected version ranges are: 3.0.x before 3.0.12, 3.1.x before 3.1.14, 3.2.x before 3.2.12, and 3.3.x before 3.3.3 (GitHub Advisory).
The root cause is classified as CWE-130 (Improper Handling of Length Parameter Inconsistency), where HAProxy fails to validate the length field of the NEW_TOKEN format against the actual length of the associated data. This allows a network-based attacker with no privileges or user interaction required to send crafted input that exploits the missing length check. Exploitation requires high attack complexity, suggesting specific conditions or timing must be met. A patch commit is publicly available in the HAProxy 3.2 repository (GitHub Advisory, HAProxy Commit).
Successful exploitation results in low integrity and low availability impacts, with no confidentiality impact. An attacker could cause partial disruption to HAProxy's availability (e.g., service instability or denial of service conditions) and limited unauthorized data modification. The scope is unchanged, meaning the impact is confined to the vulnerable HAProxy component itself without lateral movement to other systems (GitHub Advisory).
Users should upgrade to the following fixed versions: HAProxy Community Edition 3.0.12, 3.1.14, 3.2.12, or 3.3.3. HAProxy Enterprise and ALOHA users should consult their vendor for corresponding patched releases. The fix is available in the HAProxy source repository (HAProxy Commit). No configuration-based workarounds have been publicly documented; upgrading to a patched version is the recommended remediation (GitHub Advisory, HAProxy).
HAProxy published a blog post addressing CVE-2026-26081 alongside related QUIC denial-of-service issues (HAProxy Blog). Debian issued DSA-6130-1 and Ubuntu issued USN-8036-1 covering this vulnerability, and openSUSE released a corresponding security update. Linux security news outlets covered the distribution-level advisories, and Tenable added detection plugins (IDs 298912 and 300391) for the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."