PT-2026-32395 · Haproxy+2 · Haproxy+2

·

CVE-2026-33555

·

Published

2026-04-13

·

Updated

2026-06-30

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HAProxy versions 2.6 through 3.3.5
Description The HTTP/3 parser fails to verify that the received body length aligns with a previously announced content-length when a stream is closed using a frame with an empty payload. This discrepancy can lead to desynchronization between the proxy and the backend server, potentially enabling request smuggling, which is a technique used to interfere with the way a website processes sequences of HTTP requests.
Recommendations Update to version 3.3.6 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-HAPROXY-2026-33555
CVE-2026-33555
OESA-2026-2083
OESA-2026-2084
OESA-2026-2085
OESA-2026-2086
OPENSUSE-SU-2026:10581-1
OPENSUSE-SU-2026:20618-1
RHSA-2026:8749
SUSE-SU-2026:1568-1
SUSE-SU-2026:21280-1
SUSE-SU-2026:21289-1
SUSE-SU-2026:21318-1
SUSE-SU-2026:21353-1
SUSE-SU-2026:21390-1
USN-8208-1

Affected Products

Haproxy
Linuxmint
Ubuntu