PT-2026-95708 · Suricata · Suricata

CVE-2026-71418

·

Published

2026-08-19

·

Updated

2026-09-26

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Suricata versions 8.0.0 through 8.0.5
Description DNS-over-HTTP/2 processing in the file rust/src/http2/http2.rs fails to clear the internal buffer, retaining contents from previously processed HTTP/2 DATA frames. When multiple DATA frames with the EndOfStream flag are sent, the buffer can expand to its 65 KiB limit, forcing the system to re-process all prior contents. This results in quadratic CPU complexity, which can lead to degraded packet processing, loss of monitoring visibility, or a denial of service.
Recommendations Update to version 8.0.6.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71418
GHSA-XJGQ-3QW4-JP5F

Affected Products

Suricata