Suricata · Suricata · CVE-2026-63449
**Name of the Vulnerable Software and Affected Versions**
Suricata versions 8.0.0 through 8.0.5
**Description**
The SIP parser in `rust/src/sip/parser.rs` stores request and response body lengths in 16-bit fields. When a SIP body exceeds 65,536 bytes, the length is truncated. This prevents `frame:request.body` or `frame:response.body` from exposing the full body for inspection, which allows content in the omitted section to bypass frame-based detection.
**Recommendations**
Update to version 8.0.6.