Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Suricata processes DNS-over-HTTP/2 traffic. A flaw in the Rust implementation keeps earlier DATA frame payloads in an internal buffer rather than clearing them. When an attacker sends multiple DATA frames with the EndOfStream flag, the buffer can grow to its 65 KiB limit and the engine re‑processes all prior contents on each new frame. This quadratic CPU usage can stall packet processing, cause loss of monitoring visibility and ultimately lead to a denial of service. The weakness is categorized as CWE‑407, unsafe recursion/iteration that results in uncontrolled resource consumption.

Affected Systems

OISF Suricata versions 8.0.0 through 8.0.6. The issue was fixed in release 8.0.6. All earlier releases in the 8.0.x series are vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact. EPSS is not available, so current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. A likely attack vector is network‑based; an attacker can trigger the exploit by sending crafted HTTP/2 DATA frames to a Suricata deployment over the Internet or an internal network. The vulnerability requires no local privileges or authentication and therefore can affect any host running the vulnerable Suricata version.

Generated by OpenCVE AI on September 19, 2026 at 11:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 8.0.6 or newer to remove the buffer reuse flaw.
  • Reconfigure Suricata to disable DNS‑over‑HTTP/2 processing if the environment permits until the patch is applied.
  • Deploy monitoring to track CPU usage and packet processing metrics, ensuring the quadratic behavior has been mitigated.

Generated by OpenCVE AI on September 19, 2026 at 11:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6.
Title Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:47:25.146Z

Reserved: 2026-08-06T16:28:51.181Z

Link: CVE-2026-71418

cve-icon Vulnrichment

Updated: 2026-09-21T19:48:45.347Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:18:08.590

Modified: 2026-09-28T18:39:56.660

Link: CVE-2026-71418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity