cbcvebase.
CVE-2026-26080
published 2026-07-20

CVE-2026-26080: HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also…

PriorityP416low3.7CVSS 3.1
AVNACHPRNUINSUCNINAL
EPSS
0.42%
34.1th percentile
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianhaproxy< haproxy 3.2.11-2 (forky)haproxy 3.2.11-2 (forky)
haproxyhaproxy>= 3.2 < 3.2.123.2.12
haproxyhaproxy>= 3.3 < 3.3.33.3.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.