{"id":"CVE-2026-22263","summary":"Suricata http1: quadratic complexity in headers parsing over multiple packets","details":"Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.","aliases":["GHSA-rwc5-hxj6-hwx7"],"modified":"2026-08-12T03:51:40.984577134Z","published":"2026-01-27T18:27:45.351Z","related":["openSUSE-SU-2026:10082-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-1050"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22263.json"},"references":[{"type":"WEB","url":"https://redmine.openinfosecfoundation.org/issues/8201"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22263.json"},{"type":"ADVISORY","url":"https://github.com/OISF/suricata/security/advisories/GHSA-rwc5-hxj6-hwx7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22263"},{"type":"FIX","url":"https://github.com/OISF/suricata/commit/018a377f74e3eb2b042c6f783ad9043060923428"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oisf/suricata","events":[{"introduced":"9956286fb89f9cad9e9f95b99dc751f8666617b7"},{"fixed":"3bd9f773bdc65d7bede2f0576790a68fb68b7476"},{"fixed":"018a377f74e3eb2b042c6f783ad9043060923428"}],"database_specific":{"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.0.3"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*"}}],"versions":["suricata-8.0.2","suricata-8.0.1","suricata-8.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22263.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}