CVE-2026-26080
EUVD-2026-4598820.07.2026, 16:16
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haproxy | haproxy | 3.2 ≤ 𝑥 < 3.2.12 |
| haproxy | haproxy | 3.3 ≤ 𝑥 < 3.3.3 |
| haproxy | aloha | 17.0.0 ≤ 𝑥 < 17.0.18 |
| haproxy | aloha | 17.5.0 ≤ 𝑥 < 17.5.16 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
| haproxy | haproxy_enterprise | 3.2r1:r1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration