{"id":"CVE-2026-33555","details":"An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.","aliases":["BIT-haproxy-2026-33555"],"modified":"2026-07-18T08:15:46.254996Z","published":"2026-04-13T00:00:00Z","related":["SUSE-SU-2026:1568-1","SUSE-SU-2026:21280-1","SUSE-SU-2026:21289-1","SUSE-SU-2026:21318-1","SUSE-SU-2026:21353-1","SUSE-SU-2026:21390-1","openSUSE-SU-2026:10581-1","openSUSE-SU-2026:20618-1"],"database_specific":{"cwe_ids":["CWE-130"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33555.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://r3verii.github.io/cve/2026/04/14/haproxy-h3-standalone-fin-smuggling.html"},{"type":"WEB","url":"https://www.haproxy.com/documentation/haproxy-aloha/changelog/"},{"type":"WEB","url":"https://www.haproxy.org"},{"type":"WEB","url":"https://www.mail-archive.com/haproxy@formilux.org/msg46752.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33555.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33555"},{"type":"FIX","url":"https://github.com/haproxy/haproxy/commit/05a295441c621089ffa4318daf0dbca2dd756a84"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/haproxy/haproxy","events":[{"introduced":"a1efc048bf8a5e14466dbe7317e73117e8d66176"},{"fixed":"d76ee72d03b088ad4616ff8bbee439798d5f18d6"},{"fixed":"05a295441c621089ffa4318daf0dbca2dd756a84"}],"database_specific":{"extracted_events":[{"introduced":"2.6.0"},{"fixed":"3.3.6"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*"}}],"versions":["v3.4-dev6","v3.4-dev5","v3.4-dev4","v3.4-dev3","v3.4-dev2","v3.4-dev1","v3.4-dev0","v3.3.0","v3.3-dev14","v3.3-dev13","v3.3-dev12","v3.3-dev11","v3.3-dev10","v3.3-dev9","v3.3-dev8","v3.3-dev7","v3.3-dev6","v3.3-dev5","v3.3-dev4","v3.3-dev3","v3.3-dev2","v3.3-dev1","v3.3-dev0","v3.2.0","v3.2-dev17","v3.2-dev16","v3.2-dev15","v3.2-dev14","v3.2-dev13","v3.2-dev12","v3.2-dev11","v3.2-dev10","v3.2-dev9","v3.2-dev8","v3.2-dev7","v3.2-dev6","v3.2-dev5","v3.2-dev4","v3.2-dev3","v3.2-dev2","v3.2-dev1","v3.2-dev0","v3.1.0","v3.1-dev14","v3.1-dev13","v3.1-dev12","v3.1-dev11","v3.1-dev10","v3.1-dev9","v3.1-dev8","v3.1-dev7","v3.1-dev6","v3.1-dev5","v3.1-dev4","v3.1-dev3","v3.1-dev2","v3.1-dev1","v3.1-dev0","v3.0.0","v3.0-dev13","v3.0-dev12","v3.0-dev11","v3.0-dev10","v3.0-dev9","v3.0-dev8","v3.0-dev7","v3.0-dev6","v3.0-dev5","v3.0-dev4","v3.0-dev3","v3.0-dev2","v3.0-dev1","v3.0-dev0","v2.9.0","v2.9-dev12","v2.9-dev11","v2.9-dev10","v2.9-dev9","v2.9-dev8","v2.9-dev7","v2.9-dev6","v2.9-dev5","v2.9-dev4","v2.9-dev3","v2.9-dev2","v2.9-dev1","v2.9-dev0","v2.8.0","v2.8-dev13","v2.8-dev12","v2.8-dev11","v2.8-dev10","v2.8-dev9","v2.8-dev8","v2.8-dev7","v2.8-dev6","v2.8-dev5","v2.8-dev4","v2.8-dev3","v2.8-dev2","v2.8-dev1","v2.8-dev0","v2.7.0","v2.7-dev10","v2.7-dev9","v2.7-dev8","v2.7-dev7","v2.7-dev6","v2.7-dev5","v2.7-dev4","v2.7-dev3","v2.7-dev2","v2.7-dev1","v2.7-dev0","v2.6.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-33555.json","vanir_signatures_modified":"2026-07-18T08:15:46Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["335704238780208405744808584555352514080","311113376879804669213655689694242463002","154709578920224520401428879263846628246","160484607314480768930869884862911896190"],"threshold":0.9},"id":"CVE-2026-33555-250d0764","signature_type":"Line","signature_version":"v1","source":"https://github.com/haproxy/haproxy/commit/05a295441c621089ffa4318daf0dbca2dd756a84","target":{"file":"src/h3.c"}},{"deprecated":false,"digest":{"length":4823,"function_hash":"299947196058118186086508109364719660837"},"id":"CVE-2026-33555-638460a3","signature_type":"Function","signature_version":"v1","source":"https://github.com/haproxy/haproxy/commit/05a295441c621089ffa4318daf0dbca2dd756a84","target":{"file":"src/h3.c","function":"h3_rcv_buf"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"}]}