The vulnerability exists due to inadequate validation of content lengths within the centralized HTTP compression module. The application passes nested, malformed zip or gzip headers directly to the decompressor without an effective upper bound, triggering extreme memory exhaustion that forces the operating system to kill the Suricata process.