Brotli Compression Vulnerability in Suricata Network Security Monitoring Engine
CVE-2026-63452
7.5HIGH
What is CVE-2026-63452?
Suricata, a prominent network intrusion detection and prevention system, has a vulnerability that arises from the HTTP/1 parser's handling of decompression processes. Versions 8.0.0 through 8.0.6 have an inadequate limit on the number of small Brotli compression bombs a single flow can submit, especially when the response-body-decompress-layer-limit feature is enabled. This flaw enables attackers to submit repeated compressed responses, leading to excessive resource consumption during decompression. This not only degrades packet processing efficiency but can also result in significant monitoring visibility loss or lead to a denial of service scenario. The issue has been addressed in Suricata version 8.0.6.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6
