4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Description
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Basic Information
ID
CVE-2026-33555
Source
mitre
Published
Apr 13, 2026 at 00:00
Modified
Apr 13, 2026 at 16:22
Affected Product
Vendor
HAProxy
Product
HAProxy
Version
2.6
Affected Versions
HAProxy HAProxy 2.6