Length Check Flaw in HAProxy Community Edition and Enterprise Versions
CVE-2026-26081

4.8MEDIUM

Key Information:

Vendor

Haproxy

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-26081?

A vulnerability exists in HAProxy Community Edition versions 3.0 through 3.3 prior to 3.3.3, where the software lacks a proper length check for the NEW_TOKEN format. This oversight can lead to potential exploitation risks that affect the integrity and security of the product, impacting both the Community and Enterprise variants, including HAProxy ALOHA. Ensuring prompt updates to patched versions is crucial to mitigate any associated security risks.

Affected Version(s)

HAProxy 3.0 < 3.0.12

HAProxy 3.1 < 3.1.14

HAProxy 3.2 < 3.2.12

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.