PT-2026-95708 · Suricata · Suricata
CVE-2026-71418
·
Published
2026-08-19
·
Updated
2026-09-26
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Suricata versions 8.0.0 through 8.0.5
Description
DNS-over-HTTP/2 processing in the file
rust/src/http2/http2.rs fails to clear the internal buffer, retaining contents from previously processed HTTP/2 DATA frames. When multiple DATA frames with the EndOfStream flag are sent, the buffer can expand to its 65 KiB limit, forcing the system to re-process all prior contents. This results in quadratic CPU complexity, which can lead to degraded packet processing, loss of monitoring visibility, or a denial of service.Recommendations
Update to version 8.0.6.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suricata