7.5

CVE-2026-45759

Suricata http1: quadratic Content-Disposition processing can lead to denial of service

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP `Content-Disposition` headers during HTTP response body processing. Crafted HTTP traffic could cause excessive CPU usage and denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, use a rule like `alert http1 any any -> any any (sid: 1; http.request_header; content: "Content-Disposition:"; startswith; bsize: > 8192; bypass;)`.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oisf ≫ Suricata Version >= 7.0.0 <= 7.0.16
Oisf ≫ Suricata Version >= 8.0.0 < 8.0.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
Vendor Advisory
Release Notes
https://github.com/OISF/suricata/security/advisories/GHSA-cfq5-g2v5-6652
Vendor Advisory
https://redmine.openinfosecfoundation.org/issues/8529
Permissions Required