#VU128043 Allocation of Resources Without Limits or Throttling in Suricata - CVE-2024-38535
Published: July 11, 2024 / Updated: April 27, 2026
Suricata
Open Information Security Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the HTTP/2 parser when parsing crafted HTTP/2 traffic with duplicate headers. A remote attacker can send specially crafted HTTP/2 traffic to cause a denial of service.