CVE-2026-26080: Haproxy Aloha

Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.

HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

Affected products

  • Haproxy Aloha: from 17.0.0, before 17.0.18 (fixed in 17.0.18); from 17.5.0, before 17.5.16 (fixed in 17.5.16)
  • Haproxy Haproxy: from 3.2, before 3.2.12 (fixed in 3.2.12); from 3.3, before 3.3.3 (fixed in 3.3.3)
  • Haproxy Haproxy Enterprise: version 3.2r1 only

Published 2026-07-20. Last modified 2026-08-25.