r3verii@r3veriiDisclosure
A newly disclosed CVE‑2026‑33555 involves cross‑protocol smuggling via a standalone QUIC FIN in HAProxy's HTTP/3 implementation; technical details are provided in a linked blog post.
/r/netsec@_r_netsecDisclosure
The text discloses a new HAProxy vulnerability (CVE-2026-33555) involving cross‑protocol smuggling triggered by a standalone QUIC FIN, providing technical details but no evidence of exploitation, patching, or false‑positive status.
Marius Avram@securityshellDisclosure
The article announces a Desync cross‑protocol smuggling vulnerability in HAProxy’s HTTP/3 implementation that can be triggered via a Standalone QUIC FIN packet, providing technical details but no evidence of active exploitation or patches.
Security Harvester@secharvesterxDisclosure
The article announces a new HAProxy vulnerability (CVE‑2026‑33555) involving cross‑protocol smuggling via a standalone QUIC FIN.
Ferramentas Linux@Cezar_H_LinuxPatch
The tweet announces the release of a Debian patch for the HAProxy request smuggling vulnerability CVE‑2026‑33555 and directs readers to a guide for details.
Ferramentas Linux@Cezar_H_LinuxDisclosure
The tweet discloses a new HAProxy HTTP/3 request smuggling vulnerability (CVE-2026-33555) that can desynchronize connection pools and hijack user sessions, with a link for further details.
CCB Alert@CCBalertDisclosure
The message announces a medium‑severity vulnerability in HAProxy (CVE-2026-33555) that could enable request smuggling, providing only the CVE identifier, severity score, and attack vector, with no evidence of exploitation or remediation.