- What: An integer underflow vulnerability exists in haproxy when handling QUIC packets.
- Impact: A remote attacker can send a specially crafted request to the server, trigger an integer underflow, and perform a denial of service attack.
- Affected: Ubuntu.
- CVE: CVE-2026-26081
- Patch: Install update from vendor's website.
Main Vulnerability Database SB2026021280 SB2026021280 - Ubuntu update for haproxy Published: February 12, 2026 Security Bulletin ID SB2026021280 Severity Medium Patch available YES Number of vulnerabilities 1 Exploitation vector Remote access Highest impact Denial of service Breakdown by Severity Low Medium High Critical Description This security bulletin contains information about 1 security vulnerability. 1) Integer underflow (CVE-ID: CVE-2026-26081) The vulnerability allows a remote attacker to perform a denial of service attack. The vulnerability exists due to integer underflow when handling QUIC packets. A remote attacker can send a specially crafted request to the server, trigger an integer underflow and perform a denial of service attack. Remediation Install update from vendor's website. References https://ubuntu.com/security/notices/USN-8036-1