{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/haproxy-community-edition/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":3.7,"id":"CVE-2026-26080"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HAProxy Community Edition","HAProxy Enterprise","ALOHA","HAProxy Community Edition \u003c 3.3.3"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","vulnerability","haproxy","load-balancer"],"_cs_type":"advisory","_cs_vendors":["HAProxy"],"content_html":"\u003cp\u003eA denial of service (DoS) vulnerability, identified as CVE-2026-26080, has been disclosed affecting HAProxy Community Edition versions 3.2.x up to, but not including, 3.3.3, as well as HAProxy Enterprise and ALOHA products. This flaw stems from improper handling of varint, a method of serializing integers, which can cause the HAProxy instance to enter an infinite loop or crash unexpectedly. Such an event would severely disrupt the availability and performance of applications and services relying on HAProxy for load balancing and proxying. While the full technical details of exploitation are not provided, successful exploitation would lead to service outages and potential data path disruption for affected organizations. The vulnerability specifically targets the core functionality of HAProxy, making it a critical concern for environments deploying these versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe primary impact of CVE-2026-26080 is a denial of service for any applications or services utilizing vulnerable versions of HAProxy. If exploited, the HAProxy instance could crash or become unresponsive, leading to service outages, degraded performance, and unavailability of critical network resources. Organizations relying on HAProxy for high availability and load balancing could experience significant operational disruption, reputational damage, and potential financial losses due to prolonged downtime. The vulnerability affects a broad range of HAProxy deployments, including enterprise and appliance-based solutions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-26080 by upgrading HAProxy Community Edition to version 3.3.3 or newer immediately on all affected servers. Consult HAProxy Enterprise and ALOHA documentation for specific patch instructions.\u003c/li\u003e\n\u003cli\u003eReview HAProxy configurations for unusual traffic patterns that might indicate attempts to trigger the varint mishandling vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T07:33:18Z","date_published":"2026-07-23T07:32:02Z","id":"https://feed.craftedsignal.io/briefs/2026-07-haproxy-dos/","summary":"A denial of service vulnerability (CVE-2026-26080) in HAProxy Community Edition versions 3.2.x through 3.3.x before 3.3.3, HAProxy Enterprise, and ALOHA can lead to a loop or crash due to mishandled varint, impacting service availability.","title":"HAProxy Denial of Service Vulnerability (CVE-2026-26080)","url":"https://feed.craftedsignal.io/briefs/2026-07-haproxy-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - HAProxy Community Edition","version":"https://jsonfeed.org/version/1.1"}