UbuntuUpdates.org

Package "haproxy"

Name: haproxy

Description:

fast and reliable load balancing reverse proxy

Latest version: 3.0.12-0ubuntu0.25.10.4
Release: questing (25.10)
Level: security
Repository: main
Homepage: http://www.haproxy.org/

Links


Download "haproxy"


Other versions of "haproxy" in Questing

Repository Area Version
base main 3.0.10-1ubuntu3
base universe 3.0.10-1ubuntu3
security universe 3.0.12-0ubuntu0.25.10.4
updates main 3.0.12-0ubuntu0.25.10.4
updates universe 3.0.12-0ubuntu0.25.10.4

Changelog

Version: 3.0.12-0ubuntu0.25.10.4 2026-04-27 13:11:05 UTC

  haproxy (3.0.12-0ubuntu0.25.10.4) questing-security; urgency=medium

  * SECURITY UPDATE: HTTP/3 parser request smuggling issue
    - debian/patches/CVE-2026-33555.patch: check body size with
      content-length on empty FIN in src/h3.c.
    - CVE-2026-33555

 -- Marc Deslauriers <email address hidden> Wed, 15 Apr 2026 14:02:22 -0400

Source diff to previous version
CVE-2026-33555 An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced conten

Version: 3.0.12-0ubuntu0.25.10.3 2026-02-12 20:07:56 UTC

  haproxy (3.0.12-0ubuntu0.25.10.3) questing-security; urgency=medium

  * SECURITY UPDATE: crash via INITIAL packet for the NEW_TOKEN format
    - debian/patches/quic-reject-invalid-token.patch: reject invalid token
      in src/quic_token.c.
    - CVE-2026-26081

 -- Marc Deslauriers <email address hidden> Tue, 10 Feb 2026 07:50:15 -0500

CVE-2026-26081 BUG/MAJOR: quic: reject invalid token



About   -   Send Feedback to @ubuntu_updates