CVE-2026-22261
Description
A flaw was found in Suricata, a network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring (NSM) engine. Various inefficiencies in its eXtended Forwarded For (XFF) handling, particularly for alerts not triggered in a transaction, can lead to severe slowdowns. This vulnerability could allow a remote attacker to cause a Denial of Service by sending specially crafted network traffic.
Statement
This is a LOW impact denial of service vulnerability in Suricata's XFF handling. Red Hat products shipping Suricata are not affected by default, as XFF support is disabled by default in the eve configuration. Exploitation would require an administrator to explicitly enable XFF support.
Mitigation
To mitigate this issue, ensure that XFF support is disabled in the Suricata eve configuration. This setting is disabled by default, so no action is required unless it has been explicitly enabled. If XFF support has been enabled, it can be disabled in the Suricata configuration file. A service restart may be required for changes to take effect.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other); Reduce Performance
This issue can make the product perform more slowly. If an attacker can influence the number of iterations in the loop, then this performance problem might allow a denial of service by consuming more platform resources than intended.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.