Skip to main content
EPSS 0.3%top 78%

An issue was discovered in HAProxy before 3.3.6. (CVE-2026-33555)

0
Medium
Published: 06/30/2026 (06/30/2026, 23:39:33 UTC)
Source: GCVE Database
Product: haproxy

Description

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

Affected software

Bitnamimore threats →ghsa
haproxy
pkg:bitnami/haproxy
Affected versions
>=2.6.0 <3.3.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:53:58 UTC

Technical Analysis

CVE-2026-33555 is a vulnerability in HAProxy's HTTP/3 parser where it fails to verify that the received body length matches the announced content-length if a stream closes with an empty payload. This flaw can cause desynchronization with the backend server, enabling HTTP request smuggling attacks. Such attacks may allow an attacker to bypass security mechanisms and access unauthorized resources. The vulnerability is tracked under CWE-130 (Improper Handling of Length Parameter Inconsistency). Red Hat has published an advisory (RHSA-2026:8749) addressing this issue in Red Hat Hardened Images RPMs, specifically haproxy-3.0.19-1.1.hum1 for aarch64 and x86_64 architectures. No patch or mitigation that meets Red Hat's standards for ease of deployment and applicability is currently available. The vulnerability has medium severity, with a network attack vector and high attack complexity, requiring no privileges or user interaction. Red Hat remains the authoritative source for this vulnerability's impact on its products.

Potential Impact

The vulnerability allows remote attackers to perform HTTP request smuggling by exploiting a desynchronization between the frontend HTTP/3 parser and the backend server. This can lead to bypassing security controls and potentially accessing unauthorized resources. The impact is rated as medium with low integrity impact and no confidentiality or availability impact according to Red Hat's assessment. The attack complexity is high, and no privileges or user interaction are required.

Mitigation Recommendations

Currently, no mitigation is available or meets Red Hat's criteria for ease of use, deployment, applicability, or stability. Users should monitor Red Hat advisories for updates regarding patches or mitigations. Until a fix is released, consider limiting exposure of affected HAProxy instances to untrusted networks if possible. Customers with Red Hat Technical Account Managers (TAM) can consult them for tailored guidance. Applying a fix is recommended once it becomes available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:8749
Cve Count
1

Threat ID: 6a4049d327e9c7971982c5c9

Added to database: 06/27/2026, 22:08:19 UTC

Last enriched: 08/16/2026, 17:53:58 UTC

Last updated: 09/12/2026, 10:01:30 UTC

Views: 30

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses