Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63446

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transactions remain unmarked, are never freed, and are repeatedly rescanned. The per-flow list can grow without bound with quadratic cleanup cost, causing CPU and memory exhaustion. This issue is fixed in version 8.0.6.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 32.8%
CVSS Severity
CVSS v3 Score 7.5


Contact Us

Shodan ® - All rights reserved