CVE-2026-26081
Received Received - Intake

Buffer Overflow in HAProxy Community Edition

Vulnerability report for CVE-2026-26081, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: MITRE

Description

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
haproxy aloha *
haproxy community_edition From 3.0 (inc) to 3.3.3 (exc)
haproxy enterprise *
haproxy community_edition From 3.0|end_excluding=3.3.3 (inc)
haproxy community_edition From 3.0.0 (inc) to 3.3.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-130 The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HAProxy Community Edition versions 3.0 through 3.3 before 3.3.3 are vulnerable due to missing length validation for the NEW_TOKEN format. This flaw could allow improper handling of tokens, potentially leading to unexpected behavior or security issues.

Detection Guidance

The provided CVE data does not include specific detection methods or commands for identifying this vulnerability on a network or system. Check HAProxy documentation or security advisories for updates on detection techniques.

Impact Analysis

An attacker might exploit this to cause denial of service or manipulate token-based operations. Systems relying on HAProxy for load balancing or proxy services could experience instability or incorrect processing of requests.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with GDPR, HIPAA, or other standards. The vulnerability involves a lack of length check for the NEW_TOKEN format in HAProxy, which could lead to potential security issues like unauthorized data modification or disruption of services. However, without explicit details on data exposure or processing, its direct effect on compliance remains unclear.

Mitigation Strategies

Upgrade HAProxy Community Edition to version 3.3.3 or later. If using HAProxy Enterprise or ALOHA, apply the latest patches provided by the vendor.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-26081. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart