cbcvebase.
CVE-2026-26081
published 2026-07-20

CVE-2026-26081: HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

PriorityP426medium4.8CVSS 3.1
AVNACHPRNUINSUCNILAL
EPSS
0.36%
28.8th percentile
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianhaproxy< haproxy 3.2.11-2 (forky)haproxy 3.2.11-2 (forky)
haproxyhaproxy>= 3.0 < 3.0.123.0.12
haproxyhaproxy>= 3.1 < 3.1.143.1.14
haproxyhaproxy>= 3.2 < 3.2.123.2.12
haproxyhaproxy>= 3.3 < 3.3.33.3.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.