Impact
Suricata, an IDS/IPS and network security monitoring engine, has a flaw in its HTTP/1 parser. From versions 8.0.0 through 8.0.6, the parser limits decompression work per transaction but does not restrict the number of small Brotli‑compressed responses a flow can submit. When response‑body‑decompress‑layer‑limit is enabled, an attacker can send many compressed responses. Each transaction triggers costly Rust htp decompression, causing high CPU consumption, degraded packet processing, potential loss of monitoring visibility, and denial of service. The flaw is an instance of resource exhaustion and improper handling of compression bombs (CWE‑400, CWE‑409).
Affected Systems
The vulnerability affects the Suricata engine distributed by the Open Information Security Foundation. All releases from 8.0.0 up to and including 8.0.6 are impacted. The issue was fixed in version 8.0.6 and later, so upgrading to that or newer releases removes the flaw.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. EPSS data is not available, and Suricata is not listed in the CISA KEV catalogue, so no current exploitation reports are known. The vulnerability can be triggered by sending crafted HTTP traffic to any Suricata instance with HTTP/1 inspection enabled; no authentication or privileged access is required. Consequently, the attack vector is network traffic that the IDS/IPS examines. Because the flaw is driven solely by the volume of responses, an adversary with the ability to generate repeated Brotli‑compressed HTTP responses can exhaust system resources, leading to degraded performance or denial of service.
OpenCVE Enrichment