Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33555

28
FAUCET Score

CVE-2026-33555 is an HTTP/3 parser validation flaw in HAProxy versions 2.6 through 3.3.5 that fails to verify the received body length matches the announced content-length header when streams close via empty payload frames. This validation gap creates desynchronization between HAProxy and backend servers, enabling potential HTTP request smuggling attacks. The vulnerability carries a CVSS v3.1 base score of 4.0 (MEDIUM) with a network attack vector, high attack complexity, and no special privileges required. The impact is limited to integrity violations with no confidentiality or availability impact. The EPSS score of 0.00012 indicates minimal real-world exploitation likelihood relative to the broader CVE ecosystem. The vulnerability shows no active exploitation status, with no known public exploit code available and no inclusion in the CISA Known Exploited Vulnerabilities catalog. The inactive status on security hot lists suggests limited community attention and low immediate threat prioritization. Organizations running HAProxy should plan upgrades to version 3.3.6 or later within normal patch management cycles.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.0, < 3.3.6CPE matchmatch criteria
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*
>= 2.6, < 3.3.6CPE match
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
21.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 12th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 haproxy 2.9.11-4 on Azure Linux 3.0Fixed in: 2.9.11-5
microsoftpatch availablevia msrc
Product: azl3 haproxy 2.9.11-5 on Azure Linux 3.0Fixed in: 2.9.11-5
microsoftpatch availablevia msrc
Product: 21285-17084Fixed in: 2.9.11-5
microsoftpatch availablevia msrc
Product: 20734-17084Fixed in: 2.9.11-5

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-33555Moderate

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

Apr 14, 2026

References

github.com / haproxy/haproxy/commit/05a295441c621089ffa4318daf0dbca2dd756a84
Patch
r3verii.github.io / cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html
ExploitThird Party Advisory
haproxy.com / documentation/haproxy-aloha/changelog
Release Notes
haproxy.org
Product
mail-archive.com / [email protected]/msg46752.html
Release Notes