HomeOisfCVE-2025-53538

CVE-2025-53538

HIGH
7.5CVSS
Published: 2025-07-22
Updated: 2025-10-06
AI Analysis

Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.0.10 and below and 8.0.0-beta1 through 8.0.0-rc1, mishandling of data on HTTP2 stream 0 can lead to uncontrolled memory usage, leading to loss of visibility. Workarounds include disabling the HTTP/2 parser, and using a signature like drop http2 any any -> any any (frame:http2.hdr; byte_test:1,=,0,3; byte_test:4,=,0,5; sid: 1;) where the first byte test tests the HTTP2 frame type DATA and the second tests the stream id 0. This is fixed in versions 7.0.11 and 8.0.0.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
high
Weaknesses
CWE-400CWE-770

Metadata

Primary Vendor
OISF
Published
7/22/2025
Last Modified
10/6/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

oisf : suricataoisf : suricataoisf : suricata

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-53538 | HIGH Severity | CVEDatabase.com | CVEDatabase.com