CVE-2026-22263

Description

A flaw was found in Suricata, a network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring (NSM) engine. A remote attacker can exploit an inefficiency in HTTP/1 header parsing by sending multiple packets with specially crafted headers. This can lead to a significant slowdown in the system's performance, resulting in a Denial of Service (DoS).

Statement

This vulnerability has a MODERATE impact. Inefficiency in HTTP/1 header parsing over multiple packets in Suricata versions 8.0.0 through 8.0.2 can lead to a denial of service (slowdown). Red Hat customers using Suricata as a network IDS/IPS/NSM engine that processes untrusted HTTP/1 traffic may be affected.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other); Reduce Performance

This issue can make the product perform more slowly. If an attacker can influence the number of iterations in the loop, then this performance problem might allow a denial of service by consuming more platform resources than intended.

Frequently Asked Questions

Want to get errata notifications? Sign up here.