Stack Overflow Vulnerability in Suricata Network Engine Affects OISF
CVE-2025-64331

7.5HIGH

Key Information:

Vendor

Oisf

Status
Vendor
CVE Published:
26 November 2025

What is CVE-2025-64331?

Suricata, a prominent network intrusion detection and prevention system, has a vulnerability that may lead to a stack overflow during large HTTP file transfers. This issue arises when users increase the HTTP response body limit and enable logging of printable HTTP bodies. The vulnerability is mitigated in versions 7.0.13 and 8.0.2. Users are advised to revert to default HTTP response body limits or disable http-body-printable logging, which is disabled by default, as a precautionary measure.

Affected Version(s)

suricata < 7.0.13 < 7.0.13

suricata < 8.0.2 < 8.0.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.