CVE-2026-33555: Medium severity HAProxy HAProxy vulnerability
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33555?
CVE-2026-33555 is classified as a moderate severity vulnerability due to potential desynchronization issues with backend servers.
How do I fix CVE-2026-33555?
To fix CVE-2026-33555, upgrade HAProxy to version 3.3.6 or later.
What software versions are affected by CVE-2026-33555?
CVE-2026-33555 affects HAProxy versions prior to 3.3.6.
What kind of issues can CVE-2026-33555 cause?
CVE-2026-33555 can cause desynchronization issues with the backend server due to incorrect handling of content-length.
Is there a workaround for CVE-2026-33555?
There is no documented workaround for CVE-2026-33555, so upgrading to a patched version is recommended.