Length Check Flaw in HAProxy Community Edition and Enterprise Versions
CVE-2026-26081
4.8MEDIUM
What is CVE-2026-26081?
A vulnerability exists in HAProxy Community Edition versions 3.0 through 3.3 prior to 3.3.3, where the software lacks a proper length check for the NEW_TOKEN format. This oversight can lead to potential exploitation risks that affect the integrity and security of the product, impacting both the Community and Enterprise variants, including HAProxy ALOHA. Ensuring prompt updates to patched versions is crucial to mitigate any associated security risks.
Affected Version(s)
HAProxy 3.0 < 3.0.12
HAProxy 3.1 < 3.1.14
HAProxy 3.2 < 3.2.12
