https://reddit.com/r/cybersecurity/comments/1sngpac/haproxy_http3_http1_desync_crossprotocol/: HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
Published Apr 16, 2026
·Updated
Affected Software
1 affected component
HAProxy HAProxy
Frequently Asked Questions
1
What is the severity of CVE-2026-33555?
CVE-2026-33555 is considered a high severity vulnerability due to its potential for cross-protocol request smuggling.
2
How can I mitigate CVE-2026-33555?
To mitigate CVE-2026-33555, ensure that your HAProxy configurations are reviewed for handling HTTP/3 and HTTP/1 transitions securely.
3
What systems are affected by CVE-2026-33555?
CVE-2026-33555 affects HAProxy installations that handle both HTTP/3 and HTTP/1 traffic.
4
Is a patch available for CVE-2026-33555?
Yes, a patch addressing CVE-2026-33555 has been released in the latest version of HAProxy.
5
What are the potential impacts of CVE-2026-33555?
The potential impacts of CVE-2026-33555 include unauthorized data exposure and the ability to manipulate requests between protocols.