HTTP Request Smuggling Vulnerability in HAProxy Affected by QUIC Configuration
CVE-2026-90678

7.5HIGH

Key Information:

Vendor

Haproxy

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90678?

An issue present in HAProxy versions 3.3.0 to 3.4.4 and from 3.5 development versions 1 to 5 enables HTTP request smuggling when configured with QUIC support. If an HTTP/3 request lacks a Content-Length header, the server erroneously processes chunk size, allowing attackers to exploit the deduplication of streams. By sending a larger declared payload and then prematurely ending the stream, an attacker can smuggle a request that eludes regular analysis, potentially merging their request with valid user requests, which may lead to unauthorized access or manipulation of sensitive data. The exploitation method relies on a combination of race conditions in backend connection pooling, making it a concerning vulnerability that requires prompt attention.

Affected Version(s)

HAProxy 3.3.0 <= 3.3.14

HAProxy 3.4.0 <= 3.4.4

HAProxy 3.5-dev1 <= 3.5-dev5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.