Description
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Published: 2026-07-20
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper handling of varint values, causing HAProxy to enter an infinite loop or crash. This results in a denial of service that can bring the load‑balancing service offline, disrupting availability for downstream applications. The detailed impact is inferred from the description.

Affected Systems

HAProxy Community Edition versions 3.2.x and 3.3.x before 3.3.3, as well as HAProxy Enterprise and ALOHA, are affected. The bug is tied to the core varint parsing logic and applies to all builds of these products in the mentioned version ranges.

Risk and Exploitability

The CVSS score of 3.7 places the issue in the low category, and the EPSS score of < 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation so far. Attackers would need to craft traffic that includes malformed varints; the loop or crash typically occurs during normal packet processing, so the attack could be performed remotely from outside the network. The likely attack vector is inferred from the description that malformed varints can be included in external traffic.

Generated by OpenCVE AI on August 3, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HAProxy to version 3.3.3 or later, which includes a fix for the varint handling bug.
  • For HAProxy Enterprise or ALOHA users, apply the vendor‑issued patch or update to a release that incorporates the fix.
  • If immediate upgrade is not feasible, isolate the HAProxy instance from untrusted traffic, enforce strict ACLs to validate input, and monitor logs for repeated restarts to detect exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Varint Handling Bug Causes Infinite Loop or Crash in HAProxy Community Edition

Sun, 26 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title HAProxy Varint Handling Loop and Crash Vulnerability

Tue, 21 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title HAProxy Varint Handling Loop and Crash Vulnerability

Mon, 20 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
First Time appeared Haproxy
Haproxy haproxy
Weaknesses CWE-252
CPEs cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*
Vendors & Products Haproxy
Haproxy haproxy
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-20T18:16:43.967Z

Reserved: 2026-02-11T00:00:00.000Z

Link: CVE-2026-26080

cve-icon Vulnrichment

Updated: 2026-07-20T18:16:36.877Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:30:16Z

Weaknesses