SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-26081

MEDIUM · CVSS 4.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

HAProxy Community Edition versions 3.0 to 3.3.2, along with HAProxy Enterprise and ALOHA, are vulnerable due to a missing length check for the NEW_TOKEN format, which could allow attackers to exploit this oversight. The impact includes potential denial of service or other malicious actions that could disrupt service availability. Organizations using these versions should prioritize patching to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-26081
Severity
MEDIUM
CVSS
4.8
EPSS
0.36%

Original NVD Description

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.