CVE-2026-26081

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
Configurations

No configuration.

History

20 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 16:16

Updated : 2026-07-21 19:49


NVD link : CVE-2026-26081

Mitre link : CVE-2026-26081

CVE.ORG link : CVE-2026-26081


JSON object : View

Products Affected

No product.

CWE
CWE-130

Improper Handling of Length Parameter Inconsistency