PT-2026-95652 · Suricata · Suricata

·

CVE-2026-63446

·

Published

2026-07-21

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Suricata versions 8.0.0 through 8.0.5
Description The AppLayerParserSetTransactionInspectId() function in src/app-layer-parser.c uses an inverted guard, which results in only already-inspected transactions being marked as inspected. When flows are processed via a pass rule or pass-the-flow exception policy, detection is skipped, leaving completed transactions unmarked. Consequently, these transactions are never freed and are repeatedly rescanned. This causes the per-flow list to grow without bound with quadratic cleanup cost, leading to CPU and memory exhaustion.
Recommendations Update to version 8.0.6.

Exploit

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63446
GHSA-GJWR-75GQ-877M

Affected Products

Suricata