CVE-2026-90678

NameCVE-2026-90678
DescriptionAn issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
haproxy (PTS)bookworm, bookworm (security)2.6.12-1+deb12u3fixed
trixie (security), trixie3.0.11-1+deb13u3fixed
forky, sid3.2.23-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
haproxysource(unstable)(not affected)

Notes

- haproxy <not-affected> (Vulnerable code introduced later)
Fixed by: http://git.haproxy.org/?p=haproxy.git;a=commit;h=86a4ebc761a278838e8cb06f3a292282ba704c65 (v3.5-dev6)

Search for package or bug name: Reporting problems