PT-2026-90786 · Haproxy+2 · Haproxy
CVE-2026-90678
·
Published
2026-09-13
·
Updated
2026-09-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
HAProxy versions 3.3.0 through 3.4.4
HAProxy versions 3.5-dev1 through 3.5-dev5
Description
An issue exists in HAProxy when using an HTTP/3 frontend built with QUIC support and a QUIC bind listener, where traffic is routed to a backend over HTTP/1.1 using chunked transfer coding on a reused connection. When an HTTP/3 request lacks a
Content-Length header, the HTTP/3 multiplexer uses the length declared in a DATA frame header as the HTTP/1.1 chunk size before the payload is actually received. A remote unauthenticated client can declare a payload larger than what is delivered and then end the stream, causing HAProxy to return the connection to the idle pool in a desynchronized state.This leads to HTTP request smuggling on reused backend connections, allowing an attacker to bypass frontend rules, such as path-based
http-request deny filters. Additionally, requests from concurrent clients, including their request lines and Authorization headers, may be consumed as the attacker's request body and lost. Exploitation is non-deterministic as it depends on a race condition with backend connection pooling.Recommendations
As a temporary mitigation, drop QUIC binds until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Haproxy