CyberRota Analysis
AI-GeneratedHAProxy Community Edition versions 3.0 to 3.3.2, along with HAProxy Enterprise and ALOHA, are vulnerable due to a missing length check for the NEW_TOKEN format, which could allow attackers to exploit this oversight. The impact includes potential denial of service or other malicious actions that could disrupt service availability. Organizations using these versions should prioritize patching to mitigate the risk associated with this vulnerability.
CVE
CVE-2026-26081
Severity
MEDIUM
CVSS
4.8
EPSS
0.36%
Original NVD Description
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.