Web Hack List

Preliminary research

HAProxy HTTP/3 → HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)

AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from March through September. Unranked, incomplete, not community-vetted, and subject to change.

Shows an HTTP/3-to-HTTP/1 request-smuggling flaw in HAProxy's downgrade path: a standalone QUIC FIN can terminate an H3 body without the length validation applied to a normal DATA frame. The backend then treats bytes from the next request as the unfinished H1 body, crossing user boundaries without an attacker-supplied payload body.

Record

Researcher
Martino Spagnuolo and @Martino Spagnuolo
Published by
CyberSec Notes
Date
Format
Advisory

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Martino Spagnuolo and @Martino Spagnuolo, first published at the original source. Preserved copies are kept so the citation survives its host.