CVE-2026-71418
7.5 HIGHpublic exploit availablePublished 2026-09-18 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-407
Public exploit & PoC references
All references
- https://github.com/OISF/suricata/commit/1731805967edf5d31448db2ae43cf72c6cf46c11
- https://github.com/OISF/suricata/commit/26c26dea84f00de95151a0e16d21c1fcafac9648
- https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
- https://github.com/OISF/suricata/security/advisories/GHSA-xjgq-3qw4-jp5f
- https://redmine.openinfosecfoundation.org/issues/8725
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100700PoC
- MEDIUMCVE-2026-102277PoC
- MEDIUMCVE-2026-19668
- UNSCOREDCVE-2026-42772PoC
- LOWCVE-2026-44639PoC
- HIGHCVE-2026-61814PoC
- HIGHCVE-2026-63446PoC
- HIGHCVE-2026-63447PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.