CVE-2026-22263

MEDIUM

Suricata <8.0.3 - DoS

Title source: llm
STIX 2.1

Description

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1050
Status published
Products (1)
oisf/suricata 8.0.0 - 8.0.3
Published Jan 27, 2026
Tracked Since Feb 18, 2026