CVE-2026-26081
HAProxy vulnerability analysis and mitigation

Overview

CVE-2026-26081 is a vulnerability in HAProxy Community Edition affecting versions 3.0 through 3.3 (before 3.3.3) caused by a missing length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. The vulnerability was published on July 20, 2026, and has a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory). Specific affected version ranges are: 3.0.x before 3.0.12, 3.1.x before 3.1.14, 3.2.x before 3.2.12, and 3.3.x before 3.3.3 (GitHub Advisory).

Technical details

The root cause is classified as CWE-130 (Improper Handling of Length Parameter Inconsistency), where HAProxy fails to validate the length field of the NEW_TOKEN format against the actual length of the associated data. This allows a network-based attacker with no privileges or user interaction required to send crafted input that exploits the missing length check. Exploitation requires high attack complexity, suggesting specific conditions or timing must be met. A patch commit is publicly available in the HAProxy 3.2 repository (GitHub Advisory, HAProxy Commit).

Impact

Successful exploitation results in low integrity and low availability impacts, with no confidentiality impact. An attacker could cause partial disruption to HAProxy's availability (e.g., service instability or denial of service conditions) and limited unauthorized data modification. The scope is unchanged, meaning the impact is confined to the vulnerable HAProxy component itself without lateral movement to other systems (GitHub Advisory).

Mitigation and workarounds

Users should upgrade to the following fixed versions: HAProxy Community Edition 3.0.12, 3.1.14, 3.2.12, or 3.3.3. HAProxy Enterprise and ALOHA users should consult their vendor for corresponding patched releases. The fix is available in the HAProxy source repository (HAProxy Commit). No configuration-based workarounds have been publicly documented; upgrading to a patched version is the recommended remediation (GitHub Advisory, HAProxy).

Community reactions

HAProxy published a blog post addressing CVE-2026-26081 alongside related QUIC denial-of-service issues (HAProxy Blog). Debian issued DSA-6130-1 and Ubuntu issued USN-8036-1 covering this vulnerability, and openSUSE released a corresponding security update. Linux security news outlets covered the distribution-level advisories, and Tenable added detection plugins (IDs 298912 and 300391) for the vulnerability.

Additional resources


SourceThis report was generated using AI

Related HAProxy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55203CRITICAL9
  • HAProxy logoHAProxy
  • haproxy-3.4
NoYesJun 18, 2026
CVE-2026-55204HIGH8.7
  • HAProxy logoHAProxy
  • haproxy-debuginfo
NoYesJun 18, 2026
CVE-2026-33555MEDIUM5.8
  • HAProxy logoHAProxy
  • haproxy-2.8
NoYesApr 13, 2026
CVE-2026-26081MEDIUM4.8
  • HAProxy logoHAProxy
  • cpe:2.3:a:haproxy:haproxy
NoYesJul 20, 2026
CVE-2026-26080LOW3.7
  • HAProxy logoHAProxy
  • cpe:2.3:a:haproxy:haproxy
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management