Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fields. A SIP body larger than 65,536 bytes can truncate the length and prevent frame:request.body or frame:response.body from exposing the complete body to inspection, allowing content in the omitted portion to evade frame-based detection. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Detection Evasion via SIP body truncation
Action: Patch
AI Analysis

Impact

Suricata’s SIP parser stores request and response body lengths in 16-bit fields; bodies larger than 65,536 bytes are truncated, causing frame:request.body and frame:response.body to expose only part of the message. This numeric truncation error (CWE-197) allows content beyond the 65-kilobyte limit to escape rule‑based detection engines, potentially hiding malicious payloads while the rest of the SIP message appears normal. Based on the description, it is inferred that an attacker can send SIP traffic containing a body larger than 65,536 bytes to trigger the truncation.

Affected Systems

The vulnerability affects Suricata that is distributed by the Open Information Security Foundation. Versions 8.0.0 through 8.0.6 are impacted. The issue was addressed in release 8.0.6.

Risk and Exploitability

With a CVSS score of 3.7 the vulnerability is considered moderate. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower likelihood of widespread exploitation at present. Based on the description, it is inferred that the attack does not require authentication and can be performed over the network, allowing an adversary to embed malicious payloads beyond the 65-kilobyte limit and evade frame‑based detection. This limits the impact to detection evasion rather than direct compromise.

Generated by OpenCVE AI on September 19, 2026 at 11:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.6 or later to apply the patch that restores full body length handling.
  • If an upgrade is delayed, temporarily disable SIP inspection or configure Suricata to drop SIP messages whose body exceeds 65,536 bytes to prevent evasion.
  • Continuously monitor SIP traffic for unusually large bodies and inspect logs for evidence of truncated content to detect potential abuse of the vulnerability.
  • Encapsulate SIP traffic in TLS or other secure transports to reduce the ease with which an attacker can inject large bodies.

Generated by OpenCVE AI on September 19, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fields. A SIP body larger than 65,536 bytes can truncate the length and prevent frame:request.body or frame:response.body from exposing the complete body to inspection, allowing content in the omitted portion to evade frame-based detection. This issue is fixed in version 8.0.6.
Title Suricata sip: large SIP message bodies can evade detection with frame keyword
Weaknesses CWE-197
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:47:32.828Z

Reserved: 2026-07-16T19:35:57.767Z

Link: CVE-2026-63449

cve-icon Vulnrichment

Updated: 2026-09-21T19:40:16.324Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:04.220

Modified: 2026-09-28T18:33:18.110

Link: CVE-2026-63449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses