CVE-2026-22261 - Suricata eve/alert: http1 xff handling can lead to denial of service

CVE-2026-22261 - Suricata eve/alert: http1 xff handling can lead to denial of service

CVE ID : CVE-2026-22261 Published : Jan. 27, 2026, 6:10 p.m. | 48 minutes ago Description : Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuration. The setting is disabled by default. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Jan. 27, 2026
Attack Vector: network