Количество 8
Количество 8
GHSA-5mp8-rq5m-pj7m
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
CVE-2026-33555
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser doe ...
openSUSE-SU-2026:20618-1
Security update for haproxy
SUSE-SU-2026:1568-1
Security update for haproxy
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-5mp8-rq5m-pj7m An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 4 месяца назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 4 месяца назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 4 месяца назад | |
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6. | CVSS3: 4 | 0% Низкий | 4 месяца назад | |
CVSS3: 4 | 0% Низкий | 4 месяца назад | ||
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser doe ... | CVSS3: 4 | 0% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20618-1 Security update for haproxy | 0% Низкий | 4 месяца назад | ||
SUSE-SU-2026:1568-1 Security update for haproxy | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу