Home / mailingsPDF  

[SECURITY] [DSA 6130-1] haproxy security update

Posted on 12 February 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6130-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
February 12, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : haproxy
CVE ID : CVE-2026-26081

Asim Viladi Oglu Manizada reported that HAProxy, a load balancing
reverse proxy, does not properly validate an INITIAL QUIC packet with
specially crafted data, which may result in denial of service (process
crash).

For the stable distribution (trixie), this problem has been fixed in
version 3.0.11-1+deb13u2.

We recommend that you upgrade your haproxy packages.

For the detailed security status of haproxy please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/haproxy

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP