CVE-2026-90678 | HAProxy up to 3.3.14/3.4.4/3.5-dev5 HTTP/3 Multiplexer request smuggling

A vulnerability labeled as problematic has been found in HAProxy up to 3.3.14/3.4.4/3.5-dev5. Impacted is an unknown function of the component HTTP/3 Multiplexer. Executing a manipulation can lead to http request smuggling. This vulnerability is registered as CVE-2026-90678. It is possible to launch the attack remotely. No exploit is available. The affected component should be upgraded.

Tekst info:


Gepubliceerd: 06:07 - 13 Sep 2026