PT-2026-90786 · Haproxy+2 · Haproxy

CVE-2026-90678

·

Published

2026-09-13

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions HAProxy versions 3.3.0 through 3.4.4 HAProxy versions 3.5-dev1 through 3.5-dev5
Description An issue exists in HAProxy when using an HTTP/3 frontend built with QUIC support and a QUIC bind listener, where traffic is routed to a backend over HTTP/1.1 using chunked transfer coding on a reused connection. When an HTTP/3 request lacks a Content-Length header, the HTTP/3 multiplexer uses the length declared in a DATA frame header as the HTTP/1.1 chunk size before the payload is actually received. A remote unauthenticated client can declare a payload larger than what is delivered and then end the stream, causing HAProxy to return the connection to the idle pool in a desynchronized state.
This leads to HTTP request smuggling on reused backend connections, allowing an attacker to bypass frontend rules, such as path-based http-request deny filters. Additionally, requests from concurrent clients, including their request lines and Authorization headers, may be consumed as the attacker's request body and lost. Exploitation is non-deterministic as it depends on a race condition with backend connection pooling.
Recommendations As a temporary mitigation, drop QUIC binds until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90678

Affected Products

Haproxy