CVE-2026-26080: Haproxy Aloha
Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
Affected products
- Haproxy Aloha: from 17.0.0, before 17.0.18 (fixed in 17.0.18); from 17.5.0, before 17.5.16 (fixed in 17.5.16)
- Haproxy Haproxy: from 3.2, before 3.2.12 (fixed in 3.2.12); from 3.3, before 3.3.3 (fixed in 3.3.3)
- Haproxy Haproxy Enterprise: version 3.2r1 only
Published 2026-07-20. Last modified 2026-08-25.