Preliminary research
HAProxy HTTP/3 → HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from March through September. Unranked, incomplete, not community-vetted, and subject to change.
Shows an HTTP/3-to-HTTP/1 request-smuggling flaw in HAProxy's downgrade path: a standalone QUIC FIN can terminate an H3 body without the length validation applied to a normal DATA frame. The backend then treats bytes from the next request as the unfinished H1 body, crossing user boundaries without an attacker-supplied payload body.
Record
- Researcher
- Martino Spagnuolo and @Martino Spagnuolo
- Published by
- CyberSec Notes
- Date
- Format
- Advisory
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Martino Spagnuolo and @Martino Spagnuolo, first published at the original source. Preserved copies are kept so the citation survives its host.