Allocation of Resources Without Limits or Throttling in Suricata - CVE-2024-32663
Published: May 7, 2024 / Updated: April 27, 2026
Suricata
Open Information Security Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the HTTP/2 parser when handling compressed headers. A remote attacker can send a small amount of specially crafted HTTP/2 traffic to cause a denial of service.