Loop and Crash Vulnerability in HAProxy Community Edition and Enterprise
CVE-2026-26080

3.7LOW

Key Information:

Vendor

Haproxy

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-26080?

HAProxy versions 3.2.x through 3.3.x prior to 3.3.3 experience a critical mishandling of varint that can lead to infinite loops or crashes. This impacts not only the Community Edition but also HAProxy Enterprise and ALOHA products. Users are advised to upgrade to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

HAProxy 3.2 < 3.2.12

HAProxy 3.3 < 3.3.3

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.