CVE-2026-33555
MEDIUM 5.8EPSS 0.3%
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
- CVSS v3.1
- 5.8 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N - CVSS v3.1
- 4.0 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N - EPSS
- 0.30% chance of exploitation in the next 30 days, 22th percentile
- Published
- 2026-04-13
- Updated
- 2026-04-22
Proof-of-concept exploits (1)
- r3verii/CVE-2026-335552★ · 2026-04-17