Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli compression bombs a single flow can submit. With response-body-decompress-layer-limit enabled, repeated compressed responses make the decompression paths in rust/htp perform expensive work for every transaction, degrading packet processing and potentially causing loss of monitoring visibility or denial of service. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (CPU exhaustion)
Action: Immediate Patch
AI Analysis

Impact

Suricata, an IDS/IPS and network security monitoring engine, has a flaw in its HTTP/1 parser. From versions 8.0.0 through 8.0.6, the parser limits decompression work per transaction but does not restrict the number of small Brotli‑compressed responses a flow can submit. When response‑body‑decompress‑layer‑limit is enabled, an attacker can send many compressed responses. Each transaction triggers costly Rust htp decompression, causing high CPU consumption, degraded packet processing, potential loss of monitoring visibility, and denial of service. The flaw is an instance of resource exhaustion and improper handling of compression bombs (CWE‑400, CWE‑409).

Affected Systems

The vulnerability affects the Suricata engine distributed by the Open Information Security Foundation. All releases from 8.0.0 up to and including 8.0.6 are impacted. The issue was fixed in version 8.0.6 and later, so upgrading to that or newer releases removes the flaw.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity. EPSS data is not available, and Suricata is not listed in the CISA KEV catalogue, so no current exploitation reports are known. The vulnerability can be triggered by sending crafted HTTP traffic to any Suricata instance with HTTP/1 inspection enabled; no authentication or privileged access is required. Consequently, the attack vector is network traffic that the IDS/IPS examines. Because the flaw is driven solely by the volume of responses, an adversary with the ability to generate repeated Brotli‑compressed HTTP responses can exhaust system resources, leading to degraded performance or denial of service.

Generated by OpenCVE AI on September 19, 2026 at 11:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.6 or later
  • Reboot the Suricata process to apply the patch
  • Monitor CPU usage and packet processing performance to detect any residual issues

Generated by OpenCVE AI on September 19, 2026 at 11:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli compression bombs a single flow can submit. With response-body-decompress-layer-limit enabled, repeated compressed responses make the decompression paths in rust/htp perform expensive work for every transaction, degrading packet processing and potentially causing loss of monitoring visibility or denial of service. This issue is fixed in version 8.0.6.
Title Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption
Weaknesses CWE-400
CWE-409
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T18:19:52.084Z

Reserved: 2026-07-16T19:35:57.768Z

Link: CVE-2026-63452

cve-icon Vulnrichment

Updated: 2026-09-21T18:19:48.781Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:04.667

Modified: 2026-09-28T18:40:07.333

Link: CVE-2026-63452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)