CVE-2026-33555Disclosure(haproxy / haproxy)

LOWCVSS 5.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch haproxy haproxy systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • haproxy

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 3 mentions (2026-04-16); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
haproxy

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-16: 3Mentions · 2026-04-17: 1Mentions · 2026-04-21: 1Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1PoC Mentioned / Linked · 2026-04-16: 2PoC Mentioned / Linked · 2026-04-17: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-04-16: 3Technical Details · 2026-04-17: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-24: 104-1604-1704-2105-2405-25
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-163
Disclosure3
2026-04-171
Disclosure1
2026-04-211
Disclosure1
2026-05-241
Disclosure1
2026-05-251
Patch1
Full discourse7 posts
  • r3verii@r3verii
    Disclosure

    HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555) https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html

    Post summary

    A newly disclosed CVE‑2026‑33555 involves cross‑protocol smuggling via a standalone QUIC FIN in HAProxy's HTTP/3 implementation; technical details are provided in a linked blog post.

    025214110945.3K
    95 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555) https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html

    Post summary

    The text discloses a new HAProxy vulnerability (CVE-2026-33555) involving cross‑protocol smuggling triggered by a standalone QUIC FIN, providing technical details but no evidence of exploitation, patching, or false‑positive status.

    020104672
    33.3K followersView on X
  • Marius Avram@securityshell
    Disclosure

    HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555) https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html

    Post summary

    The article announces a Desync cross‑protocol smuggling vulnerability in HAProxy’s HTTP/3 implementation that can be triggered via a Standalone QUIC FIN packet, providing technical details but no evidence of active exploitation or patches.

    02074913
    16.2K followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555) https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html https://t.co/lXBxN63IIN

    Post summary

    The article announces a new HAProxy vulnerability (CVE‑2026‑33555) involving cross‑protocol smuggling via a standalone QUIC FIN.

    11121287
    967 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    HAProxy request smuggling vuln (CVE-2026-33555) just got a Debian patch. Here's your guide Read more -> https://tinyurl.com/3sj8j4hx #Debian https://t.co/nIPGyq5u3d

    Post summary

    The tweet announces the release of a Debian patch for the HAProxy request smuggling vulnerability CVE‑2026‑33555 and directs readers to a guide for details.

    1000064
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    HAProxy HTTP/3 request smuggling (CVE-2026-33555) can desync connection pools and hijack user sessions. Read more -> http://tinyurl.com/bdebyysw #Debian https://t.co/1BfggYYrKE

    Post summary

    The tweet discloses a new HAProxy HTTP/3 request smuggling vulnerability (CVE-2026-33555) that can desynchronize connection pools and hijack user sessions, with a link for further details.

    10000101
    1.5K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: medium severity vulnerability in #HAProxy. CVE-2026-33555 CVSS: 4.0. This flaw could be exploited for request smuggling. #Patch #Patch #Patch

    Post summary

    The message announces a medium‑severity vulnerability in HAProxy (CVE-2026-33555) that could enable request smuggling, providing only the CVE identifier, severity score, and attack vector, with no evidence of exploitation or remediation.

    01000110
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaproxyhaproxy---

Explore more