Skip to content
Threat Feed

Vendor

HAProxy

6 briefs RSS
medium advisory

HAProxy Security Bypass Vulnerability

A vulnerability in HAProxy (CVE-2023-45538) allows remote, unauthenticated attackers to bypass security restrictions, manipulate data, and trigger denial-of-service conditions.

HAProxy security-bypass denial-of-service network-security
1t
high advisory

Ted Backdoor Implant in Trojanized HAProxy Binaries

North Korean state-sponsored actors are deploying a sophisticated Linux backdoor named 'ted' by replacing legitimate HAProxy binaries with trojanized versions to intercept web traffic and execute malicious commands.

HAProxy linux backdoor malware network-security
3t 8i
low advisory

Service Exhaustion via Stalled TLS ALPN Handshakes

Attackers are exploiting unpatched TLS listeners by flooding them with incomplete ACME ALPN handshakes to exhaust server-side resources like goroutines and worker threads.

PoC Traefik +7
1t 2c 2i updated
medium advisory

HAProxy Denial of Service Vulnerability (CVE-2026-26080)

A denial of service vulnerability (CVE-2026-26080) in HAProxy Community Edition versions 3.2.x through 3.3.x before 3.3.3, HAProxy Enterprise, and ALOHA can lead to a loop or crash due to mishandled varint, impacting service availability.

HAProxy Community Edition +3 denial-of-service vulnerability haproxy load-balancer
1c
high advisory

HAProxy CVE-2021-40346 Integer Overflow Leading to HTTP Request Smuggling and ACL Bypass

A critical integer overflow vulnerability, CVE-2021-40346, in HAProxy's `htx_add_header()` function allows unauthenticated attackers to bypass access control rules by crafting HTTP requests with specific header name lengths, leading to HTTP request smuggling and unauthorized access to backend paths, for which a public exploit is available.

HAProxy +4 integer-overflow http-smuggling acl-bypass webserver
2t 1c
high advisory

CVE-2026-55203 HAProxy Integer Overflow in FastCGI Handling

An integer overflow vulnerability (CVE-2026-55203) in HAProxy through version 3.4.0 allows malicious FastCGI backends to desynchronize the FCGI framing parser, leading to request routing errors, response smuggling, or memory safety issues.

HAProxy vulnerability fastcgi integer-overflow webserver proxy
2r 3t