CVE-2026-22261: low-severity vulnerability in OISF suricata
Suricata eve/alert: http1 xff handling can lead to denial of service
Published
No sign of exploitation. No public exploitation artifact known so far.
Suricata's handling of X-Forwarded-For (XFF) headers in HTTP alerts can cause the system to slow down significantly when processing certain network traffic. This vulnerability allows attackers to degrade the performance of network monitoring by sending specially crafted requests.
The vulnerability exists in Suricata's eve/alert module where inefficient XFF header processing, particularly for alerts not associated with an HTTP transaction, can cause denial of service through severe performance degradation. An attacker can exploit this by sending HTTP traffic with XFF headers that trigger the inefficient code path, causing resource exhaustion on the IDS/IPS system.
In the same product, most dangerous first.