Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26081

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

A flaw was found in HAProxy. This vulnerability, stemming from a missing length check in the NEW_TOKEN format, could allow a remote attacker to cause a low impact on data integrity and availability. This means an attacker might be able to subtly alter data or temporarily disrupt the service.

Отчет

This Moderate impact vulnerability in HAProxy stems from a missing length check in the NEW_TOKEN format, which could lead to data integrity and availability issues. The high attack complexity required for exploitation reduces the immediate risk in typical Red Hat deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5haproxyFix deferred
Red Hat Ceph Storage 5rhceph/rhceph-haproxy-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-haproxy-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/rhceph-haproxy-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/rhceph-haproxy-rhel9Fix deferred
Red Hat Ceph Storage 9rhceph-ci/haproxyFix deferred
Red Hat Ceph Storage 9rhceph/rhceph-haproxy-rhel10Fix deferred
Red Hat Ceph Storage 9rhceph/rhceph-haproxy-rhel9Fix deferred
Red Hat Enterprise Linux 10haproxyFix deferred
Red Hat Enterprise Linux 7haproxyFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2502945haproxy: HAProxy: Data integrity and availability vulnerability in NEW_TOKEN format

EPSS

Процентиль: 40%
0.00476
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS3: 4.8
nvd
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS3: 4.8
msrc
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS3: 4.8
debian
2 месяца назад

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length ...

CVSS3: 4.8
redos
3 дня назад

Уязвимость haproxy2

EPSS

Процентиль: 40%
0.00476
Низкий

4.8 Medium

CVSS3