← back
CVE-2026-22263mediumCWE-1050

Suricata http1: quadratic complexity in headers parsing over multiple packets

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
In short

Suricata's HTTP header parsing becomes very slow when processing requests split across multiple network packets, potentially causing the security system to lag or become unresponsive.

Technical detail

CWE-1050 inefficiency in HTTP/1 headers parsing exhibits quadratic complexity when headers span multiple packets, allowing an attacker to send fragmented HTTP requests that consume excessive CPU resources and degrade IDS/IPS performance without requiring authentication or special privileges.

Summary generated and translated by AI from the official description.
Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
OISF · suricata