Untriaged
Permalink
CVE-2026-22263
5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
Suricata http1: quadratic complexity in headers parsing over multiple packets
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.
References
-
https://github.com/OISF/suricata/security/advisories/GHSA-rwc5-hxj6-hwx7 x_refsource_CONFIRM
-
https://redmine.openinfosecfoundation.org/issues/8201 x_refsource_MISC
Affected products
suricata
- ==>= 8.0.0, < 8.0.3
Package maintainers
-
@magenbluten magenbluten <magenbluten@codemonkey.cc>