An issue was discovered in HAProxy before 3.3.6. (CVE-2026-33555)
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
AI Analysis
Technical Summary
CVE-2026-33555 is a vulnerability in HAProxy's HTTP/3 parser where it fails to verify that the received body length matches the announced content-length if a stream closes with an empty payload. This flaw can cause desynchronization with the backend server, enabling HTTP request smuggling attacks. Such attacks may allow an attacker to bypass security mechanisms and access unauthorized resources. The vulnerability is tracked under CWE-130 (Improper Handling of Length Parameter Inconsistency). Red Hat has published an advisory (RHSA-2026:8749) addressing this issue in Red Hat Hardened Images RPMs, specifically haproxy-3.0.19-1.1.hum1 for aarch64 and x86_64 architectures. No patch or mitigation that meets Red Hat's standards for ease of deployment and applicability is currently available. The vulnerability has medium severity, with a network attack vector and high attack complexity, requiring no privileges or user interaction. Red Hat remains the authoritative source for this vulnerability's impact on its products.
Potential Impact
The vulnerability allows remote attackers to perform HTTP request smuggling by exploiting a desynchronization between the frontend HTTP/3 parser and the backend server. This can lead to bypassing security controls and potentially accessing unauthorized resources. The impact is rated as medium with low integrity impact and no confidentiality or availability impact according to Red Hat's assessment. The attack complexity is high, and no privileges or user interaction are required.
Mitigation Recommendations
Currently, no mitigation is available or meets Red Hat's criteria for ease of use, deployment, applicability, or stability. Users should monitor Red Hat advisories for updates regarding patches or mitigations. Until a fix is released, consider limiting exposure of affected HAProxy instances to untrusted networks if possible. Customers with Red Hat Technical Account Managers (TAM) can consult them for tailored guidance. Applying a fix is recommended once it becomes available.
An issue was discovered in HAProxy before 3.3.6. (CVE-2026-33555)
Description
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-33555 is a vulnerability in HAProxy's HTTP/3 parser where it fails to verify that the received body length matches the announced content-length if a stream closes with an empty payload. This flaw can cause desynchronization with the backend server, enabling HTTP request smuggling attacks. Such attacks may allow an attacker to bypass security mechanisms and access unauthorized resources. The vulnerability is tracked under CWE-130 (Improper Handling of Length Parameter Inconsistency). Red Hat has published an advisory (RHSA-2026:8749) addressing this issue in Red Hat Hardened Images RPMs, specifically haproxy-3.0.19-1.1.hum1 for aarch64 and x86_64 architectures. No patch or mitigation that meets Red Hat's standards for ease of deployment and applicability is currently available. The vulnerability has medium severity, with a network attack vector and high attack complexity, requiring no privileges or user interaction. Red Hat remains the authoritative source for this vulnerability's impact on its products.
Potential Impact
The vulnerability allows remote attackers to perform HTTP request smuggling by exploiting a desynchronization between the frontend HTTP/3 parser and the backend server. This can lead to bypassing security controls and potentially accessing unauthorized resources. The impact is rated as medium with low integrity impact and no confidentiality or availability impact according to Red Hat's assessment. The attack complexity is high, and no privileges or user interaction are required.
Mitigation Recommendations
Currently, no mitigation is available or meets Red Hat's criteria for ease of use, deployment, applicability, or stability. Users should monitor Red Hat advisories for updates regarding patches or mitigations. Until a fix is released, consider limiting exposure of affected HAProxy instances to untrusted networks if possible. Customers with Red Hat Technical Account Managers (TAM) can consult them for tailored guidance. Applying a fix is recommended once it becomes available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:8749
- Cve Count
- 1
Threat ID: 6a4049d327e9c7971982c5c9
Added to database: 06/27/2026, 22:08:19 UTC
Last enriched: 08/16/2026, 17:53:58 UTC
Last updated: 09/12/2026, 10:01:30 UTC
Views: 30
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.