CVE-2026-26081
haproxy - security update
描述
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
如何修補 CVE-2026-26081
要修補 CVE-2026-26081,請將受影響套件升級到下列已修補版本。
- Debian/haproxy—升級至 3.0.11-1+deb13u2 或更新版本
CVE-2026-26081 正在被利用嗎?
目前沒有被利用訊號。CVE-2026-26081 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- Debian/haproxyfrom 0, < 3.0.11-1+deb13u2