<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>HAProxy Community Edition &lt; 3.3.3 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/haproxy-community-edition--3.3.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 23 Jul 2026 07:32:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/haproxy-community-edition--3.3.3/feed.xml" rel="self" type="application/rss+xml"/><item><title>HAProxy Denial of Service Vulnerability (CVE-2026-26080)</title><link>https://feed.craftedsignal.io/briefs/2026-07-haproxy-dos/</link><pubDate>Thu, 23 Jul 2026 07:32:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-haproxy-dos/</guid><description>A denial of service vulnerability (CVE-2026-26080) in HAProxy Community Edition versions 3.2.x through 3.3.x before 3.3.3, HAProxy Enterprise, and ALOHA can lead to a loop or crash due to mishandled varint, impacting service availability.</description><content:encoded><![CDATA[<p>A denial of service (DoS) vulnerability, identified as CVE-2026-26080, has been disclosed affecting HAProxy Community Edition versions 3.2.x up to, but not including, 3.3.3, as well as HAProxy Enterprise and ALOHA products. This flaw stems from improper handling of varint, a method of serializing integers, which can cause the HAProxy instance to enter an infinite loop or crash unexpectedly. Such an event would severely disrupt the availability and performance of applications and services relying on HAProxy for load balancing and proxying. While the full technical details of exploitation are not provided, successful exploitation would lead to service outages and potential data path disruption for affected organizations. The vulnerability specifically targets the core functionality of HAProxy, making it a critical concern for environments deploying these versions.</p>
<h2 id="impact">Impact</h2>
<p>The primary impact of CVE-2026-26080 is a denial of service for any applications or services utilizing vulnerable versions of HAProxy. If exploited, the HAProxy instance could crash or become unresponsive, leading to service outages, degraded performance, and unavailability of critical network resources. Organizations relying on HAProxy for high availability and load balancing could experience significant operational disruption, reputational damage, and potential financial losses due to prolonged downtime. The vulnerability affects a broad range of HAProxy deployments, including enterprise and appliance-based solutions.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2026-26080 by upgrading HAProxy Community Edition to version 3.3.3 or newer immediately on all affected servers. Consult HAProxy Enterprise and ALOHA documentation for specific patch instructions.</li>
<li>Review HAProxy configurations for unusual traffic patterns that might indicate attempts to trigger the varint mishandling vulnerability.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>haproxy</category><category>load-balancer</category></item></channel></rss>