Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33555

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

A flaw was found in HAProxy. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/3 request. The HTTP/3 parser fails to verify that the received body length matches the announced content-length when a stream is closed with an empty payload. This desynchronization with the backend server can lead to request smuggling, allowing an attacker to bypass security mechanisms and potentially access unauthorized resources.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10haproxyFix deferred
Red Hat Enterprise Linux 7haproxyNot affected
Red Hat Enterprise Linux 8haproxyNot affected
Red Hat Enterprise Linux 9haproxyFix deferred
Red Hat OpenShift Container Platform 4haproxyFix deferred
Red Hat Hardened Imageshaproxy-main-3.0.19-1.1.hum1FixedRHSA-2026:874917.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=2457920haproxy: HAProxy: Request smuggling via HTTP/3 parser desynchronization

EPSS

Процентиль: 22%
0.00297
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
4 месяца назад

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

CVSS3: 4
nvd
4 месяца назад

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

CVSS3: 4
msrc
4 месяца назад

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

CVSS3: 4
debian
4 месяца назад

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser doe ...

suse-cvrf
4 месяца назад

Security update for haproxy

EPSS

Процентиль: 22%
0.00297
Низкий

4 Medium

CVSS3