Junglewise Threat Intelligence

CVE-2026-63446: Suricata inverted flag logic in transaction cleanup

CVE-2026-63446 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: OISF Suricata. Vendors: OISF.

Executive brief

Suricata is a network security monitoring engine used to detect and prevent intrusions. An inverted logic bug in its transaction handling causes completed connections on pass-rule flows to never be marked as inspected, leading to memory leaks and CPU exhaustion as transaction lists grow without bound and are repeatedly rescanned. This can degrade or disable intrusion detection and prevention on networks handling significant traffic.

Technical details

AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard condition (checking for presence of a flag instead of absence), marking only already-inspected transactions as inspected rather than newly-completed ones. On pass-rule flows, detection is skipped so the flag is never set by DetectRunTx(), leaving transactions in the per-flow list; this causes quadratic O(n²) cleanup cost as each packet re-scans and rescans the accumulating list. An attacker or legitimate traffic pattern matching pass rules can trigger unbounded transaction accumulation and memory/CPU exhaustion.

Affected products

  • OISF Suricata 8.0.0 to 8.0.5

Timeline

  • 2026-09-18: disclosed

References

Related threats