How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Announcing HAProxy Enterprise 3.3 and HAProxy ALOHA 18.0

calendar_today April 27, 2026 person Iwan Price-Evans and Sean Meroth domain haproxy

            <p>We&#039;re excited to announce the release of HAProxy Enterprise 3.3, which brings significant advancements to the HAProxy Enterprise WAF and bot management capabilities.</p><p>The high-performance HAProxy Enterprise WAF (patent pending) now has a unified multi-engine module for simpler configuration of both the Intelligent WAF Engine and optional Core Rule Set (CRS) compatibility mode, which supports OWASP CRS v4. The HAProxy Enterprise Bot Management Module, powered by the advanced Threat Detection Engine, now offers even more robust enforcement options with an enhanced CAPTCHA module that closes the door on sophisticated bypass techniques. This release further solidifies HAProxy Enterprise as a leading Web Application and API Protection (WAAP) solution.</p><p>Alongside this release, we are also announcing HAProxy ALOHA 18.0, which delivers OWASP CRS v4 support to the <a href="http://production.int.haproxy.com/products/haproxy-aloha">HAProxy ALOHA virtual or hardware load balancer</a>.</p><p>HAProxy Enterprise 3.3 is a foundational component of the <a href="http://production.int.haproxy.com/products/haproxy-one">HAProxy One application delivery platform</a>, in which the data plane, control plane, and secure edge network work together seamlessly to deliver ultra-low-latency application delivery and sovereign edge security.</p><h2 id="new-to-haproxy-enterprise">New to HAProxy Enterprise?</h2><p><a href="http://production.int.haproxy.com/products/haproxy-enterprise">HAProxy Enterprise load balancer</a> provides high-performance load balancing for TCP, UDP, QUIC, and HTTP-based applications, high availability, an API/AI gateway, Kubernetes application routing, SSL processing, DDoS protection, bot management, global rate limiting, and a next-generation WAF. </p><p>HAProxy Enterprise combines the performance, reliability, and flexibility of our open-source core (HAProxy — the most widely used software load balancer) with ultra-low-latency security layers and world-class support. HAProxy Enterprise benefits from full-lifecycle management, monitoring, and automation (provided by HAProxy Fusion), and next-generation security layers powered by threat intelligence from HAProxy Edge and enhanced by machine learning. </p><p>Together, this flexible data plane, scalable control plane, and secure edge network form HAProxy One: the world’s fastest application delivery and security platform that is the G2 category leader in Load Balancing, API Management, Container Networking, DDoS Protection, and Web Application Firewall (WAF). </p><p>To learn more, <a href="http://production.int.haproxy.com/contact-us">contact our sales team</a> for a demonstration or <a href="http://production.int.haproxy.com/hapee-trial">request a free trial</a>.</p><h2 id="whats-new-in-haproxy-enterprise-33">What&#039;s new in HAProxy Enterprise 3.3</h2>
            
        
            
        
            <h2 id="whats-new-in-haproxy-aloha-180">What&#039;s new in HAProxy ALOHA 18.0</h2>
            
        
            
        
            <h2 id="ready-to-upgrade">Ready to upgrade?</h2><p>When you are ready to start the upgrade procedure, go to the <a href="https://www.haproxy.com/documentation/haproxy-enterprise/getting-started/upgrade/">upgrade instructions for HAProxy Enterprise</a> or the <a href="https://www.haproxy.com/documentation/haproxy-aloha/getting-started/installation/">installation instructions for HAProxy ALOHA</a>.</p><h2 id="unified-haproxy-enterprise-waf-module">Unified HAProxy Enterprise WAF module</h2>
            
        
            <img alt="" height="900" src="https://cdn.haproxy.com/img/containers/posts/unified-waf-module.png/3791fcdc5bb98c2224ec7b51541f343d/unified-waf-module.png" width="1800" />
            
        
            <p>Web applications and APIs are the primary attack surface for modern enterprises, facing a continuously evolving threat landscape that includes injection attacks, cross-site scripting, broken authentication, and more. A WAF is an essential layer of defense — one that must be accurate enough to block real threats, fast enough to avoid adding latency, and flexible enough to adapt without disrupting legitimate traffic. As architectures grow more complex, consistent WAF policy management across the entire environment becomes equally critical.</p><p><strong>HAProxy Enterprise 3.3 introduces a unified multi-engine module for the HAProxy Enterprise WAF. </strong>This module consolidates both WAF engines — the unique and powerful Intelligent WAF Engine and the CRS compatibility mode — under a common configuration interface.</p><p>The <a href="http://production.int.haproxy.com/solutions/web-application-firewall">HAProxy Enterprise WAF</a> is patent pending and recognized for its exceptional balanced accuracy (98.48%), ultra-low latency, and 100% private and local processing. The unified module brings together the Intelligent WAF Engine, powered by threat intelligence from HAProxy Edge and enhanced by machine learning, and the CRS compatibility mode, both delivering unparalleled performance within a single, consistent configuration interface.</p><p>The practical benefit is a simpler administrative experience: less configuration overhead, fewer opportunities for misconfiguration, and faster time-to-deployment. For enterprise teams managing complex or large-scale fleets, this directly improves operational velocity and reduces total cost of ownership.</p><p>When managed through HAProxy Fusion&#039;s visual security policy builder – the <a href="http://production.int.haproxy.com/blog/announcing-haproxy-fusion-2-0">Threat-Response Matrix</a> – administrators can orchestrate unified WAF policies across multi-cloud deployments from a single pane of glass.</p>
            
        
            <figure><img alt="" height="960" src="https://cdn.haproxy.com/img/containers/posts/haproxy-fusion-security-control-plane.png/97d79d0681c8cce67ac221be7379a7b3/haproxy-fusion-security-control-plane.png" width="1800" /><figcaption><p>Visual orchestration of HAProxy Enterprise’s multi-layered security with the Threat-Response Matrix in HAProxy Fusion 2.0</p>

</figcaption></figure>

            <h2 id="owasp-crs-v4-support-upgrade-at-your-own-pace">OWASP CRS v4 support — upgrade at your own pace</h2>
            
        
            <img alt="" height="900" src="https://cdn.haproxy.com/img/containers/posts/owasp-support-module.png/5ae002dbefcb6cc7f67622fdb689ea01/owasp-support-module.png" width="1800" />
            
        
            <p>The OWASP Core Rule Set (CRS) is the most widely deployed open-source WAF ruleset and is used to defend against the OWASP Top 10 and other common web attack categories. HAProxy Enterprise WAF uses the unique Intelligent WAF Engine by default, and provides an optional CRS compatibility mode for those who need it.</p><p>What sets HAProxy Enterprise WAF apart is the multi-engine architecture, where CRS works alongside the Intelligent WAF Engine to significantly boost accuracy and performance compared with standard CRS implementations. The result is a false positive rate of just 1.78% at paranoia level 2 (versus 28.36% for ModSecurity) and 15X lower latency.</p><p><strong>HAProxy Enterprise 3.3 adds native support for CRS v4</strong>, which delivers improved detection accuracy, reduced false positives, and a more granular paranoia level system that gives security teams finer control over the trade-off between protection and permissiveness.</p><p>Crucially, HAProxy Enterprise 3.3 supports CRS v3 and v4 simultaneously — without requiring plugins — enabling teams to adopt the new ruleset entirely on their own terms.</p><p>With this release, administrators can: </p><ul><li><p>load CRS v3 and v4 at the same time, applying each to different traffic segments; </p></li><li><p>set the paranoia level independently for each version, tailoring detection sensitivity to each application&#039;s risk profile; and</p></li><li><p>switch between versions or roll back at any time if needed.</p></li></ul><p>This multi-version approach removes the forced hard-cutover that has historically made WAF ruleset migrations risky. Teams can test CRS v4 against a subset of traffic while keeping CRS v3 in place for production workloads, gradually building confidence before completing the transition.</p><p>The result is access to the better accuracy and performance that CRS v4 offers — without the application disruption that has made ruleset upgrades a stressful proposition.</p><p>OWASP CRS v4 support is <strong>also available in HAProxy ALOHA 18.0</strong>, bringing the same flexible multi-version migration path to teams running the ALOHA hardware or virtual appliance.</p><h2 id="enhanced-bot-protection-with-lb-captcha">Enhanced bot protection with LB-CAPTCHA</h2>
            
        
            <img alt="" height="901" src="https://cdn.haproxy.com/img/containers/posts/bot-protection-module.png/15e56554ab9fa5a8e1585cfe49c8b417/bot-protection-module.png" width="1802" />
            
        
            <p>Automated bot traffic is one of the most pervasive challenges facing application teams today. Bots range from harmless crawlers to sophisticated tools used for application-layer DDoS, brute force attacks, web scraping, and vulnerability scanning — and modern bots are increasingly designed to evade detection by mimicking human behavior. The business impact is substantial: fraudulent transactions, degraded performance, data theft, and damage to user trust.</p><p>Building on the advanced <a href="http://production.int.haproxy.com/solutions/bot-management">Bot Management solution</a>, and the <a href="http://production.int.haproxy.com/blog/announcing-haproxy-enterprise-3-2">Threat Detection Engine</a> introduced in version 3.2, <strong>HAProxy Enterprise 3.3 extends the LB-CAPTCHA module</strong> with several capabilities designed to stop more sophisticated bots.</p><h3 id="token-based-captcha-callback-verification">Token-based CAPTCHA callback verification</h3><p>The most significant enhancement is a new token-based verification mechanism that protects the CAPTCHA callback process itself. When a user completes a <a href="http://production.int.haproxy.com/glossary/what-is-captcha">CAPTCHA challenge</a>, HAProxy generates a time-sensitive token from request headers during the initial GET request. On the subsequent POST request, the token is verified. Because automated bots typically modify their headers between requests, they produce a mismatched token and are blocked immediately — before they can reach the verification server.</p><p>This protection is enabled by default, applying to all CAPTCHA deployments without additional configuration. For environments requiring stricter security, the new <code>callback-token</code> function allows administrators to customize token generation using advanced criteria such as full HTTP or SSL client fingerprints.</p><h3 id="multiple-captcha-support">Multiple CAPTCHA support</h3><p>HAProxy Enterprise 3.3 introduces support for multiple CAPTCHAs within the same application. Administrators can now apply different CAPTCHA providers or configurations to different resources — for example, one CAPTCHA for a login endpoint and another for a checkout flow — giving security teams finer-grained, per-resource control over bot protection.</p><h3 id="custom-html-injection">Custom HTML injection</h3><p>A new <code>custom-html-file-lf</code> option enables dynamic HTML injection in CAPTCHA responses. Administrators can inject changing values on a per-request basis, allowing the rendered output to vary based on attributes such as the User-Agent string. This capability is particularly valuable in high-security deployments where static CAPTCHA pages may be more susceptible to scripted analysis.</p><h2 id="building-on-the-haproxy-one-platform">Building on the HAProxy One platform</h2><p>HAProxy Enterprise 3.3 continues a consistent trajectory of security advancement within the HAProxy One platform. HAProxy Enterprise 2.9 introduced the next-generation HAProxy Enterprise WAF, with the Intelligent WAF Engine delivering industry-leading balanced accuracy of 98.48%. HAProxy Enterprise 3.2 introduced the Threat Detection Engine to the Bot Management Module, bringing SaaS-level behavioral detection to your own infrastructure — including air-gapped environments. HAProxy Fusion 2.0 provides the centralized security control plane to orchestrate WAF, bot management, and more across large-scale, multi-cloud deployments from a single intuitive interface.</p><p>Together, these releases establish HAProxy One as a top-tier WAAP platform that delivers the sophisticated protection of a cloud SaaS solution with the uncompromised control of a localized, sovereign data plane and control plane.</p><h2 id="breaking-change-haproxy-enterprise-data-plane-api-33-updated-crt-load-endpoint-structure">Breaking change: HAProxy Enterprise Data Plane API 3.3 updated crt_load endpoint structure</h2><p>HAProxy Enterprise 3.3 releases alongside an updated version of the HAProxy Enterprise Data Plane API that includes a structural improvement to the <code>crt_load</code> endpoints. These endpoints are now correctly nested under their parent <code>crt_store</code> resource, aligning the API structure with the HAProxy configuration model, in which <code>crt-load</code> directives exist within a <code>crt-store</code> section.</p><p>The updated endpoint paths are as follows:</p><table><tbody><tr><td colspan="1" rowspan="1"><p><strong>Operation</strong></p></td><td colspan="1" rowspan="1"><p><strong>Updated Endpoint</strong></p></td></tr><tr><td colspan="1" rowspan="1"><p>List</p></td><td colspan="1" rowspan="1"><p><code>GET /services/haproxy/configuration/crt_stores/{crt_store}/crt_loads</code></p></td></tr><tr><td colspan="1" rowspan="1"><p>Create</p></td><td colspan="1" rowspan="1"><p><code>POST /services/haproxy/configuration/crt_stores/{crt_store}/crt_loads</code></p></td></tr><tr><td colspan="1" rowspan="1"><p>Get</p></td><td colspan="1" rowspan="1"><p><code>GET /services/haproxy/configuration/crt_stores/{crt_store}/crt_loads/{certificate}</code></p></td></tr><tr><td colspan="1" rowspan="1"><p>Update</p></td><td colspan="1" rowspan="1"><p><code>PUT /services/haproxy/configuration/crt_stores/{crt_store}/crt_loads/{certificate}</code></p></td></tr><tr><td colspan="1" rowspan="1"><p>Delete</p></td><td colspan="1" rowspan="1"><p><code>DELETE /services/haproxy/configuration/crt_stores/{crt_store}/crt_loads/{certificate}</code></p></td></tr></tbody></table><p>All <code>crt_load</code> operations now require the <code>{crt_store}</code> path parameter to identify the parent <code>crt-store</code> section. Clients using the previous endpoint paths should update their API calls to include the <code>crt_store</code> name in the path before upgrading to HAProxy Enterprise 3.3.</p><h2 id="deprecation-notice-haproxy-enterprise-data-plane-api-33-endpoints">Deprecation notice: HAProxy Enterprise Data Plane API 3.3 endpoints</h2><p>With the release of HAProxy Enterprise Data Plane API 3.3, two endpoint groups are being formally deprecated and scheduled for removal in v3.4.0. This notice is intended to give teams sufficient time to plan and complete their migrations.</p><p><code>/services/git</code><strong> endpoints</strong> — The Git-based configuration management endpoints are deprecated as of v3.3.0. Teams currently using these endpoints for configuration workflows should transition to alternative configuration management approaches ahead of the v3.4.0 release.</p><p><code>/services/aloha</code><strong> endpoints</strong> — The HAProxy ALOHA service management endpoints are also deprecated as of v3.3.0. Users relying on these endpoints should evaluate and adopt alternative service management workflows before upgrading to v3.4.0.</p><p>Both endpoint groups remain fully functional in v3.3.0, giving teams a stable migration window. They will be removed entirely in v3.4.0.</p><table><tbody><tr><td colspan="1" rowspan="1"><p><strong>Endpoint Group</strong></p></td><td colspan="1" rowspan="1"><p><strong>Status in v3.3.0</strong></p></td><td colspan="1" rowspan="1"><p><strong>Status in v3.4.0</strong></p></td></tr><tr><td colspan="1" rowspan="1"><p><code>/services/git</code></p></td><td colspan="1" rowspan="1"><p>Deprecated (functional)</p></td><td colspan="1" rowspan="1"><p>Removed</p></td></tr><tr><td colspan="1" rowspan="1"><p><code>/services/aloha</code></p></td><td colspan="1" rowspan="1"><p>Deprecated (functional)</p></td><td colspan="1" rowspan="1"><p>Removed</p></td></tr></tbody></table><p>Users who depend on either of these endpoint groups are encouraged to begin planning their migration now. If you have questions about suitable alternatives or need guidance on your migration path, please contact our support team.</p><h2 id="deprecation-notice-haproxy-enterprise-33-master-worker-configuration-keyword">Deprecation notice: HAProxy Enterprise 3.3 master-worker configuration keyword</h2><p>The <code>master-worker</code> keyword in <code>haproxy.cfg</code> is deprecated as of HAProxy Enterprise 3.3 and will be removed in version 3.5. Users currently enabling master-worker mode via this configuration directive should migrate to the equivalent command-line flags before upgrading to 3.5.</p><p><strong>Migration path:</strong> Replace <code>master-worker</code> in your configuration file with the <code>-W</code> flag (or <code>-Ws</code> for silent mode) passed directly to the HAProxy binary in your startup script.</p><table><tbody><tr><td colspan="1" rowspan="1"><p><strong>Deprecated (haproxy.cfg)</strong></p></td><td colspan="1" rowspan="1"><p><strong>Replacement (startup script)</strong></p></td></tr><tr><td colspan="1" rowspan="1"><p><code>master-worker</code></p></td><td colspan="1" rowspan="1"><p><code>haproxy -W -f /etc/haproxy/haproxy.cfg</code></p></td></tr></tbody></table><p>The <code>master-worker</code> keyword remains fully functional in 3.3, giving teams a stable migration window ahead of the 3.5 removal.</p><h2 id="upgrade-to-haproxy-enterprise-33-or-haproxy-aloha-180">Upgrade to HAProxy Enterprise 3.3 or HAProxy ALOHA 18.0</h2><p>When you are ready to upgrade, follow the links below.</p><table><tbody><tr><td colspan="1" rowspan="1"><p><strong>Documentation</strong></p></td><td colspan="1" rowspan="1"><p><strong>Release Notes</strong></p></td><td colspan="1" rowspan="1"><p><strong>Install Instructions</strong></p></td></tr><tr><td colspan="1" rowspan="1"><p><a href="https://www.haproxy.com/documentation/haproxy-enterprise/">HAProxy Enterprise Documentation</a></p></td><td colspan="1" rowspan="1"><p><a href="https://www.haproxy.com/documentation/haproxy-enterprise/release-notes/">HAProxy Enterprise 3.3 Release Notes</a></p></td><td colspan="1" rowspan="1"><p><a href="https://www.haproxy.com/documentation/haproxy-enterprise/getting-started/installation/">HAProxy Enterprise 3.3 Installation</a></p></td></tr><tr><td colspan="1" rowspan="1"><p><a href="https://www.haproxy.com/documentation/haproxy-aloha/">HAProxy ALOHA Documentation</a></p></td><td colspan="1" rowspan="1"><p><a href="https://www.haproxy.com/documentation/haproxy-aloha/release-notes/">HAProxy ALOHA 18.0 Release Notes</a></p></td><td colspan="1" rowspan="1"><p><a href="https://www.haproxy.com/documentation/haproxy-aloha/getting-started/installation/">HAProxy ALOHA 18.0 Installation</a></p></td></tr></tbody></table><h2 id="try-haproxy-enterprise-or-haproxy-aloha-with-a-free-trial">​Try HAProxy Enterprise or HAProxy ALOHA with a free trial</h2><p>The world’s leading platforms and cloud providers trust HAProxy Technologies to simplify, scale, and secure modern applications, APIs, and AI services in any environment. HAProxy Enterprise 3.3 and HAProxy ALOHA 18.0 continue our commitment to delivering industry-leading application delivery and security without compromise. Whether you&#039;re running HAProxy Enterprise as a software data plane or HAProxy ALOHA as a hardware or virtual appliance, these releases give you the tools to adopt the latest WAF standards and manage your security posture with greater simplicity — all within the HAProxy One platform.</p><p>To see for yourself, request a free trial: </p><ul><li><p><a href="http://production.int.haproxy.com/hapee-trial">HAProxy Enterprise free trial</a> </p></li><li><p><a href="http://production.int.haproxy.com/aloha-trial">HAProxy ALOHA free trial</a></p></li></ul>
            
        
        The post <a href="https://www.haproxy.com/blog/announcing-haproxy-enterprise-3-3-and-haproxy-aloha-18-0">Announcing HAProxy Enterprise 3.3 and HAProxy ALOHA 18.0</a> appeared first on <a href="https://www.haproxy.com">HAProxy Technologies</a>.
open_in_new Read original post