Bug 2531480 (CVE-2026-46387) - CVE-2026-46387 suricata: Suricata: Denial of Service via HTTP/2 decompression bomb
Summary: CVE-2026-46387 suricata: Suricata: Denial of Service via HTTP/2 decompression...
Keywords:
Status: NEW
Alias: CVE-2026-46387
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-10 14:35 UTC by OSIDB Bzimport
Modified: 2026-09-11 14:43 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-10 14:35:15 UTC
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A crafted HTTP/2 DATA payload using a high compression ratio, such as gzip, deflate, or brotli compressed data, could cause Suricata to allocate excessive memory while decompressing the payload. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable HTTP2.


Note You need to log in before you can comment on or make changes to this bug.