CVE-2026-33555 Details
Description
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
A vulnerability exists in HAProxy versions prior to 3.3.6, including 2.6, within the HTTP/3 parser. The issue arises because the parser fails to verify that the received body length aligns with a previously declared content-length when the stream is terminated with a frame containing an empty payload. This oversight can lead to desynchronization with the backend server, potentially facilitating request smuggling exploits.
Users can upgrade to HAProxy version 3.3.6 or later, or to version 2.6.25, which includes the necessary fix. Instructions for downloading these versions are available on the HAProxy website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/haproxy/haproxy/commit/05a295441c621089ffa4318daf0dbca2dd756a84 | [email protected] | Patch |
| https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html | [email protected] | ExploitThird Party Advisory |
| https://www.haproxy.com/documentation/haproxy-aloha/changelog/ | [email protected] | Release Notes |
| https://www.haproxy.org | [email protected] | Product |
| https://www.mail-archive.com/[email protected]/msg46752.html | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-130 | Improper Handling of Length Parameter Inconsistency | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| haproxy haproxy | >= 2.6.0, < 3.3.6 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 13, 2026 | New CVE Received | [email protected] |