https://reddit.com/r/netsec/comments/1snem8w/haproxy_http3_http1_desync_crossprotocol/: HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
Published Apr 16, 2026
·Updated
Affected Software
1 affected component
HAProxy HAProxy (HTTP/3 standalone mode)
Frequently Asked Questions
1
What is the severity of CVE-2026-33555?
CVE-2026-33555 is rated as a medium severity vulnerability that can lead to HTTP request smuggling.
2
How do I fix CVE-2026-33555?
To fix CVE-2026-33555, update to the latest version of HAProxy that addresses this vulnerability.
3
What systems are affected by CVE-2026-33555?
CVE-2026-33555 affects HAProxy when operating in HTTP/3 standalone mode.
4
What is the impact of CVE-2026-33555?
The impact of CVE-2026-33555 includes the potential for cross-protocol request smuggling, which can compromise web application security.
5
Is there a workaround for CVE-2026-33555?
Disabling HTTP/3 standalone mode may serve as a temporary workaround for CVE-2026-33555 until a patch is applied.