CVE-2026-26081: Haproxy Aloha

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

Affected products

  • Haproxy Aloha: from 16.5.0.0, before 16.5.30 (fixed in 16.5.30); from 17.0.0, before 17.0.18 (fixed in 17.0.18); from 17.5.0, before 17.5.16 (fixed in 17.5.16)
  • Haproxy Haproxy: from 3.0.0, before 3.0.16 (fixed in 3.0.16); from 3.1, before 3.1.14 (fixed in 3.1.14); from 3.2, before 3.2.12 (fixed in 3.2.12); from 3.3, before 3.3.3 (fixed in 3.3.3)
  • Haproxy Haproxy Enterprise: version 3.0r1 only; version 3.1r1 only; version 3.2r1 only

Published 2026-07-20. Last modified 2026-08-25.