CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Fraqueza
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Produtos afetados
- haproxy haproxy
Referências
- https://github.com/haproxy/haproxy/commit/05a295441c621089ffa4318daf0dbca2dd756a84
- https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html
- https://www.haproxy.com/documentation/haproxy-aloha/changelog/
- https://www.haproxy.org
- https://www.mail-archive.com/[email protected]/msg46752.html
- https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.