7.5

CVE-2026-46387

Suricata http2: decompression bomb can cause denial of service in Suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A crafted HTTP/2 DATA payload using a high compression ratio, such as gzip, deflate, or brotli compressed data, could cause Suricata to allocate excessive memory while decompressing the payload. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oisf ≫ Suricata Version < 7.0.16
Oisf ≫ Suricata Version >= 8.0.0 < 8.0.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
Release Notes
https://github.com/OISF/suricata/security/advisories/GHSA-45p7-j5wm-8wrx
Vendor Advisory
Mitigation
https://redmine.openinfosecfoundation.org/issues/8513
Permissions Required