CVE-2026-33555 is an HTTP request-smuggling vulnerability in HAProxy versions 2.6 through before 3.3.6. The HTTP/3 parser fails to verify that the body length received on a stream matches a previously declared Content-Length when the stream is closed by a frame with an empty payload. This can cause HAProxy and an upstream backend to disagree about request boundaries, enabling HTTP request desynchronization.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained proof-of-concept lab for HTTP request smuggling against HAProxy's HTTP/3/QUIC handling. The main exploit logic is in client/poc.py, a Python aioquic-based client that establishes an H3 connection and deliberately desynchronizes request framing by sending POST headers with a nonzero Content-Length and then terminating the QUIC stream with a zero-length FIN. According to the included description, HAProxy forwards the request to the backend as HTTP/1.1 with the declared Content-Length but no body, leaving the backend waiting for bytes that are later taken from the next request on the reused backend connection. Repository structure: - client/poc.py: primary exploit implementation and CLI. Supports continuous poisoning, single-shot verification, and test mode. Parameters include target host, port, content length, target path, inter-frame delay, and loop interval. - client/requirements.txt and client/Dockerfile: Python runtime for the PoC using aioquic. - haproxy/Dockerfile: builds HAProxy 3.0.18 with USE_QUIC=1 and quictls/OpenSSL QUIC support, then generates a self-signed certificate. - haproxy/haproxy.cfg: vulnerable lab configuration. Frontend listens on TCP and QUIC port 10002, advertises Alt-Svc for h3, and critically enables 'http-reuse always' in the backend. - nginx/default.conf plus html files: backend behavior used to trigger the bug. POST /photos causes an early 301 redirect while /status returns a stable 200 for verification. - docker-compose.yml: orchestrates haproxy, nginx, and client containers. - README.md: explains the vulnerability, prerequisites, and reproduction steps. Exploit capability: this is not an RCE exploit; it is a network/web desynchronization exploit demonstrating cross-user HTTP request smuggling through HAProxy's backend connection pool. The attacker poisons a pooled backend connection over H3/QUIC, then a separate victim request can be misparsed by the backend. The PoC verifies success by causing a victim GET /status to receive HTTP 400 instead of the expected 200. Notable targeting details: the lab explicitly targets HAProxy 3.0.18 built with QUIC/H3 support and configured with backend connection reuse. The backend is nginx 1.27, but nginx is mainly used to provide the early-response behavior necessary to expose the desync. The exploit is operational and reproducible in the provided Docker environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.