{"id":"AZL-93000","summary":"CVE-2026-26081 affecting package haproxy for versions less than 2.9.11-8","details":"HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.","modified":"2026-08-30T05:26:50Z","published":"2026-07-20T16:16:57Z","upstream":["CVE-2026-26081"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26081"}],"affected":[{"package":{"name":"haproxy","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/haproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.11-8"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93000.json"}}],"schema_version":"1.9.0"}