CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-26080: HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

lowCVSS 3.7CVE-2026-26080

CSIRTS triage

What
HAProxy can enter a loop or crash due to mishandling of varint.
Who is affected
Users of HAProxy Community Edition versions 3.2.x to 3.3.x before 3.3.3.
Urgency
Low urgency as the CVSS score is 3.7, indicating low severity.
Action
Upgrade to HAProxy version 3.3.3 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch HAProxy Community Edition

Get an email when a new HAProxy Community Edition advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
low — CVSS 3.7
Published
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26080

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-26080coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for HAProxy Community Edition

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Microsoft Security Response Center