Improper handling of highly compressed data in Suricata - CVE-2026-46387
Published: June 3, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the HTTP/2 decompression path when processing compressed HTTP/2 DATA payloads. A remote attacker can send a specially crafted compressed payload to cause a denial of service.
The issue can cause excessive memory allocation while decompressing gzip, deflate, or brotli-compressed response bodies.