CVE-2026-33555 is an HTTP/3 parser validation flaw in HAProxy versions 2.6 through 3.3.5 that fails to verify the received body length matches the announced content-length header when streams close via empty payload frames. This validation gap creates desynchronization between HAProxy and backend servers, enabling potential HTTP request smuggling attacks. The vulnerability carries a CVSS v3.1 base score of 4.0 (MEDIUM) with a network attack vector, high attack complexity, and no special privileges required. The impact is limited to integrity violations with no confidentiality or availability impact. The EPSS score of 0.00012 indicates minimal real-world exploitation likelihood relative to the broader CVE ecosystem. The vulnerability shows no active exploitation status, with no known public exploit code available and no inclusion in the CISA Known Exploited Vulnerabilities catalog. The inactive status on security hot lists suggests limited community attention and low immediate threat prioritization. Organizations running HAProxy should plan upgrades to version 3.3.6 or later within normal patch management cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.0, < 3.3.6CPE matchmatch criteria | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* | ||
>= 2.6, < 3.3.6CPE match | cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.