Impact
Suricata, the network intrusion detection and prevention engine, contains a quadratic parsing flaw when processing large HTTP Content‑Disposition headers in response bodies. This flaw can cause the engine to repeatedly perform expensive operations on the header, rapidly exhausting CPU resources. The result is a denial of service that can prevent Suricata from monitoring traffic. The weakness is a type of resource exhaustion flaw (CWE‑400).
Affected Systems
The issue affects OISF Suricata releases earlier than 7.0.16 and 8.0.5. Any deployment running a pre‑fix version of these major lines is vulnerable. Versions 7.0.16 through 7.0.x (before patch) and 8.0.5 through 8.0.x (before patch) are specifically identified as impacted. Upgrading to the mentioned fixed releases removes the vulnerability.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity. Attackers can trigger it by sending crafted HTTP responses to the Suricata instance; no local privilege or code execution is required. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that publicly available exploits are not known. Nonetheless, the ability to induce a denial of service makes the risk significant for environments relying on Suricata’s continuous monitoring capability.
OpenCVE Enrichment