CVE-2026-26080: Low severity HAProxy Technologies HAProxy Community Edition vulnerability
Published Jul 20, 2026
·Updated
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Affected Software
3 affected components
HAProxy Technologies HAProxy Community Edition>=3.2.0<3.3.3
HAProxy Technologies HAProxy Enterprise
HAProxy Technologies ALOHΑ
Event History
Jul 20, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-26080?
CVE-2026-26080 has a severity rating of low, specifically a score of 3.7.
2
What software is affected by CVE-2026-26080?
CVE-2026-26080 affects HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3, as well as HAProxy Enterprise and ALOHA.
3
What type of vulnerability is CVE-2026-26080?
CVE-2026-26080 is a vulnerability that can cause HAProxy to enter a loop or crash due to mishandling of varint.
4
How do I fix CVE-2026-26080?
To fix CVE-2026-26080, update HAProxy to version 3.3.3 or later.
5
What impact does CVE-2026-26080 have on my system?
CVE-2026-26080 can cause service disruption by making HAProxy crash or enter a loop, affecting application availability.