CVE-2026-22261: Suricata eve/alert: http1 xff handling can lead to denial of service
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuration. The setting is disabled by default.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22261?
CVE-2026-22261 is considered a denial of service vulnerability that can lead to severe slowdowns in affected Suricata versions.
How do I fix CVE-2026-22261?
To fix CVE-2026-22261, upgrade to Suricata version 8.0.3 or 7.0.14 or later.
What causes CVE-2026-22261 in Suricata?
CVE-2026-22261 is caused by inefficiencies in handling xff for alerts not triggered in a transaction.
Is my Suricata installation affected by CVE-2026-22261?
If you are using Suricata versions prior to 8.0.3 or 7.0.14, your installation is affected by CVE-2026-22261.
Can CVE-2026-22261 be exploited remotely?
Yes, CVE-2026-22261 can be exploited remotely, potentially leading to a denial of service situation.