CVE-2026-33555

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Configurations

No configuration.

History

22 Apr 2026, 19:17

Type Values Removed Values Added
References () https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html - () https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html -

22 Apr 2026, 16:16

Type Values Removed Values Added
References
  • () https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html -

13 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-13 17:16

Updated : 2026-04-22 19:17


NVD link : CVE-2026-33555

Mitre link : CVE-2026-33555

CVE.ORG link : CVE-2026-33555


JSON object : View

Products Affected

No product.

CWE
CWE-130

Improper Handling of Length Parameter Inconsistency