CVE-2026-26081
EUVD-2026-4598920.07.2026, 16:16
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| haproxy | haproxy | 3.0 ≤ 𝑥 < 3.0.12 | CNA |
| haproxy | haproxy | 3.1 ≤ 𝑥 < 3.1.14 | CNA |
| haproxy | haproxy | 3.2 ≤ 𝑥 < 3.2.12 | CNA |
| haproxy | haproxy | 3.3 ≤ 𝑥 < 3.3.3 | CNA |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration