Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transactions remain unmarked, are never freed, and are repeatedly rescanned. The per-flow list can grow without bound with quadratic cleanup cost, causing CPU and memory exhaustion. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Resource exhaustion leading to denial of service
Action: Patch
AI Analysis

Impact

The vulnerability arises in the Suricata 8.0.0 through 8.0.6 code that handles app-layer transactions. On flows that are intentionally passed by a pass rule or policy, the parser marks only already-inspected transactions and fails to free completed ones. As a result, each unmarked transaction is rescanned repeatedly, causing the per-flow list to grow without limit and triggering quadratic clean-up costs. This leads to excessive CPU usage and memory consumption, effectively denying service to legitimate traffic. The weakness maps to CWE-401 (Memory Leak) and CWE-407 (Improper Handling of Unchecked Data).

Affected Systems

Open Information Security Foundation’s Suricata engine, versions 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5 are affected; all later releases are not impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates moderate‑to‑high severity. Based on the description, it is inferred that exploitation is feasible over the network; an attacker can craft traffic that triggers pass rules and forces repeated transaction rescans. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the potential for significant service disruption remains high. Once the Exploit conditions are met, the attack can be performed remotely without authentication, leading to a denial of service for any host running the vulnerable Suricata version.

Generated by OpenCVE AI on September 19, 2026 at 11:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.6 or later
  • Reduce or remove pass rules that allow flows to bypass detection to limit repeated rescans
  • Monitor system resources and implement traffic shaping or rate limiting to mitigate any residual load spikes

Generated by OpenCVE AI on September 19, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transactions remain unmarked, are never freed, and are repeatedly rescanned. The per-flow list can grow without bound with quadratic cleanup cost, causing CPU and memory exhaustion. This issue is fixed in version 8.0.6.
Title Suricata app-layer: passed flows can retain transactions, causing resource exhaustion
Weaknesses CWE-401
CWE-407
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T16:20:22.712Z

Reserved: 2026-07-16T19:35:57.767Z

Link: CVE-2026-63446

cve-icon Vulnrichment

Updated: 2026-09-21T16:20:18.285Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:03.763

Modified: 2026-09-28T18:34:40.520

Link: CVE-2026-63446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:45:08Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-407

    Inefficient Algorithmic Complexity