CVE-2026-26081
MEDIUM
NVD
CVSS Score
4.8
Severity
MEDIUM
Published
Jul 20, 2026
Vendor
unknown
Description
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.