PT-2026-95658 · Suricata · Suricata

CVE-2026-63452

·

Published

2026-07-21

·

Updated

2026-09-26

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Suricata versions 8.0.0 through 8.0.5
Description The HTTP/1 parser limits decompression work per transaction but fails to limit the number of small brotli compression bombs a single flow can submit. When the response-body-decompress-layer-limit is enabled, repeated compressed responses force the decompression paths in rust/htp to perform expensive operations for every transaction. This can degrade packet processing, potentially leading to a denial of service or loss of monitoring visibility.
Recommendations Update to version 8.0.6.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63452
GHSA-J9CX-W9XM-5X84

Affected Products

Suricata