Suricata · Suricata · CVE-2026-63446
**Name of the Vulnerable Software and Affected Versions**
Suricata versions 8.0.0 through 8.0.5
**Description**
The `AppLayerParserSetTransactionInspectId()` function in `src/app-layer-parser.c` uses an inverted guard, which results in only already-inspected transactions being marked as inspected. When flows are processed via a pass rule or pass-the-flow exception policy, detection is skipped, leaving completed transactions unmarked. Consequently, these transactions are never freed and are repeatedly rescanned. This causes the per-flow list to grow without bound with quadratic cleanup cost, leading to CPU and memory exhaustion.
**Recommendations**
Update to version 8.0.6.