Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-26081

Опубликовано: 20 июл. 2026
Источник: debian

Описание

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
haproxyfixed3.2.11-2package
haproxynot-affectedbookwormpackage
haproxynot-affectedbullseyepackage

Примечания

  • Fixed by: https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=a05eade0f07483e6b6d0b61b1749e9093647e802 (v3.0.16)

  • Fixed by: https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=4765277f4f915baac2d57db63538ff0a59966deb (v3.2.12)

Связанные уязвимости

CVSS3: 4.8
ubuntu
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS3: 4.8
redhat
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS3: 4.8
nvd
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS3: 4.8
msrc
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS3: 4.8
redos
3 дня назад

Уязвимость haproxy2