Description
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, when an HTTP/3 request carries no Content-Length header, the HTTP/3 multiplexer credits the length declared in a DATA frame header to the stream endpoint's known-input-payload estimate at the moment the frame header is decoded, before the payload has been received, and that declared length is emitted verbatim as the HTTP/1.1 chunk size. A remote unauthenticated client that declares more payload than it delivers and then ends the stream causes HAProxy to announce a chunk larger than the bytes it writes and to return the connection to the idle pool in a desynchronized state. The result is potential HTTP request smuggling on reused backend connections: an attacker can place a request past a frontend rule such as a path-based http-request deny, so that the smuggled request is never seen by HAProxy's HTTP analysis, and can cause concurrent clients' requests, including their request lines and Authorization headers, to be consumed as the attacker's request body and lost. Exploitation is not deterministic; it depends on a race with backend connection pooling, succeeding in a majority of but not all trials during testing, and can be retried freely. The mechanism was introduced in 3.3-dev10; releases 3.2.x and earlier are unaffected.
Published: 2026-09-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Request Smuggling leading to backend connection desynchronization
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when HAProxy, built with QUIC support and configured with an HTTP/3 frontend, estimates the payload length from a DATA frame header before the payload arrives and emits that length as an HTTP/1.1 chunk size. If the declared length exceeds the data written, HAProxy announces a chunk larger than the bytes it writes, leaving the connection in a desynchronized state. This can smuggle a request past HAProxy’s HTTP analysis, allowing an attacker to inject a request that is later interpreted by the backend as the body of a concurrent client request, potentially bypassing access controls and corrupting session data.

Affected Systems

The flaw affects HAProxy versions 3.3.0 through 3.4.4 and the development releases 3.5‑dev1 through 3.5‑dev5. The issue is only exploitable when the binary is built with QUIC support and a QUIC bind listener is configured for an HTTP/3 frontend. Earlier releases in the 3.2 branch and below are immune.

Risk and Exploitability

The potential for request smuggling and subsequent loss of confidentiality, integrity, and availability of other connections. EPSS not listed in the CISA KEV catalogue, suggesting a low exploitation probability at present. The exploit requires a remote, unauthenticated client to send an HTTP/3 request with a mismatched payload size and to time the transmission such that the it is nondeterministic but can be repeated freely once conditions are met.

Generated by OpenCVE AI on September 15, 2026 at 17:32 UTC.

Remediation

Vendor Solution

Upgrade to a release or backported Enterprise version containing fix ("BUG/MAJOR: h3: reject H3 truncated frames"), first shipped in 3.5-dev6.


Vendor Workaround

Removing the QUIC bind listeners from all frontends eliminates exposure, since an HTTP/3 frontend is required. Releases in the 3.2 branch and earlier do not contain the mechanism.


OpenCVE Recommended Actions

  • Upgrade HAProxy to a release containing the fix, such as from 3.5 Enterprise backport.
  • If upgrading is not feasible, remove QUIC bind listeners from all frontends to eliminate exposure to HTTP/3 request smuggling.
  • Alternatively, disable QUIC/HTTP/3 support entirely if it is not required, or reconfigure the frontends to avoid using HTTP/3 frontends while maintaining required services.

Generated by OpenCVE AI on September 15, 2026 at 17:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title HTTP/3 Request Smuggling Exploit via Chunk Length Mismatch in HAProxy haproxy: HAProxy: HTTP Request Smuggling via HTTP/3 Multiplexer Desynchronization
Weaknesses CWE-444
References
Metrics threat_severity

None

threat_severity

Important


Mon, 14 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title HTTP/3 Request Smuggling Exploit via Chunk Length Mismatch in HAProxy

Sun, 13 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title HTTP/3 Request Smuggling via Chunked Transfer Coding in HAProxy

Sun, 13 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Haproxy
Haproxy haproxy
Vendors & Products Haproxy
Haproxy haproxy

Sun, 13 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title HTTP/3 Request Smuggling via Chunked Transfer Coding in HAProxy

Sun, 13 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, when an HTTP/3 request carries no Content-Length header, the HTTP/3 multiplexer credits the length declared in a DATA frame header to the stream endpoint's known-input-payload estimate at the moment the frame header is decoded, before the payload has been received, and that declared length is emitted verbatim as the HTTP/1.1 chunk size. A remote unauthenticated client that declares more payload than it delivers and then ends the stream causes HAProxy to announce a chunk larger than the bytes it writes and to return the connection to the idle pool in a desynchronized state. The result is potential HTTP request smuggling on reused backend connections: an attacker can place a request past a frontend rule such as a path-based http-request deny, so that the smuggled request is never seen by HAProxy's HTTP analysis, and can cause concurrent clients' requests, including their request lines and Authorization headers, to be consumed as the attacker's request body and lost. Exploitation is not deterministic; it depends on a race with backend connection pooling, succeeding in a majority of but not all trials during testing, and can be retried freely. The mechanism was introduced in 3.3-dev10; releases 3.2.x and earlier are unaffected.
Weaknesses CWE-130
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:48:00.475Z

Reserved: 2026-09-13T03:37:55.518Z

Link: CVE-2026-90678

cve-icon Vulnrichment

Updated: 2026-09-14T15:47:56.554Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T04:17:25.227

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-90678

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-13T03:37:55Z

Links: CVE-2026-90678 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency

  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')