CVE-2026-57224

high

Description

The vulnerability exists due to inadequate validation of content lengths within the centralized HTTP compression module. The application passes nested, malformed zip or gzip headers directly to the decompressor without an effective upper bound, triggering extreme memory exhaustion that forces the operating system to kill the Suricata process.

Details

Source: Mitre, NVD

Published: 2026-07-23

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High