CVE-2026-26081: Medium severity HAProxy Technologies HAProxy Community Edition vulnerability
Published Jul 20, 2026
·Updated
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEWTOKEN format. HAProxy Enterprise and ALOHA are also affected.
Affected Software
4 affected componentsFixes available
HAProxy Technologies HAProxy Community Edition>=3.0<3.3.3
HAProxy Technologies HAProxy Enterprise
HAProxy Technologies ALOHΑ
Microsoft azl3 haproxy 2.9.11-8<2.9.11-8
2.9.11-8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.9.11-8
Event History
Jul 20, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Jul 23, 2026
Data Sourced
via Microsoft·08:05 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:05 AM
Affected Software
Updated
via Microsoft·08:05 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-26081?
The severity of CVE-2026-26081 is classified as medium with a score of 4.8.
2
How do I fix CVE-2026-26081?
To fix CVE-2026-26081, upgrade HAProxy to version 3.3.3 or later.
3
What software is affected by CVE-2026-26081?
CVE-2026-26081 affects HAProxy Community Edition versions 3.0 through 3.3 and also impacts HAProxy Enterprise and ALOHA.
4
What type of vulnerability is CVE-2026-26081?
CVE-2026-26081 is a lack of length check vulnerability associated with the NEW_TOKEN format.
5
What are the potential impacts of CVE-2026-26081?
CVE-2026-26081 can lead to issues with data integrity as it allows for a potential length overflow.