MEDIUM 4.0 Microsoft
CVE-2026-33555
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Microsoft Security Update 2026-Apr: An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.
Affected Products
- azl3 haproxy 2.9.11-4 on Azure Linux 3.0
- azl3 haproxy 2.9.11-5 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33555
- https://nvd.nist.gov/vuln/detail/CVE-2026-33555
This medium severity vulnerability with a CVSS score of 4.0 was published on 2026-04-14 via Microsoft. Affected: azl3 haproxy 2.9.11-4 on Azure Linux 3.0, azl3 haproxy 2.9.11-5 on Azure Linux 3.0.
vulnfeed aggregates 14156 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.